Caveat verdict
aikek-api
aikek
Accesses credentials AND makes external network calls
Crypto research and image generation API client that generates a local Solana keypair solely for authentication signing (not holding funds), stores credentials at restricted permissions, and sends them only to the declared api.alphakek.ai endpoint with an explicit warning to never send to other domains.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls โ potential credential theft
LLM02 ยท ASI03
Accesses credentials AND encodes data โ may obfuscate stolen credentials
LLM02 ยท ASI03 ยท ASI04
Accesses credentials AND writes files โ may persist stolen credentials locally
LLM02 ยท LLM06 ยท ASI03
Permission integrity
network_out
file_read+write
credential_access
Findings (1)
POSTs data to external URL
SKILL.md ยท code ยท .post(
"https://
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class F). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
credential_accessnetwork_outdata_encodingfile_write Thanks โ recorded.