Caveat verdict
aifrens-onboard
The skill provides onboarding functionality for AI Frens, with no clear malicious behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
aifrens.ts · prose · downgraded · TOKEN: '0xF1572d1Da5c3CcE14eE5a1c9327d17e9ff0E3f43
Possible prompt injection — attempts to redefine agent identity
onboard.ts · prose · downgraded · You are now
Accesses sensitive environment variables
aifrens.ts · prose · downgraded · process.env.WALLET_PRIVATE_KEY
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.