Caveat verdict
ai-governance-intel
An AI governance intelligence tool covering regulatory frameworks (EU AI Act, US EO 14110, etc.) with a AIGC metadata header containing opaque watermarking codes; these appear to be standard Chinese AI-generated content provenance metadata, not executable code or exfiltration payloads, and the content itself is a legitimate policy research tool.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Uses eval() โ can execute arbitrary code
SKILL.md ยท code ยท eval (
Long base64 string (100+ chars) โ likely obfuscated payload
SKILL.md ยท frontmatter ยท d/nnDyDqlH0BkZsH747eEiHPbEsJ8DVkxisrCtc8/0n7+bWb2LoJADy3+Br7vVRqFN/oD7iAjXRfS6O9
Permissions & capabilities
No declared permissions โ minimal attack surface.
dynamic_eval Is this flag fair?
Thanks โ recorded.