Caveat verdict
aixin
aichat
The skill enables AI agents to communicate with each other and involves network interactions. While it seems legitimate, network output capabilities can be risky if not properly validated.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
HTTP request to bare IP address — common in malicious payloads
README.md · prose · downgraded · http://43.135.138.144
Python os.getenv — reads environment variable
main.py · prose · downgraded · os.getenv(
Permissions & capabilities
No declared permissions — minimal attack surface.
network_out Is this flag fair?
Thanks — recorded.