Caveat verdict

airoom-ltd-global-finance-data-platform

45
๐ŸŸ  Risky
Significant risk patterns flagged โ€” automated deep scan, not behavioral proof.

The skill uses Playwright to scrape files from a specific external site (airoom.ltd) and stores WordPress credentials in a config file; while no concrete exfiltration is shown, the combination of credential storage, headless browser automation targeting a specific external domain, and cryptographic reservation codes in the frontmatter is unusual and warrants caution.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

75
security
50
transparency
70
maintenance

Permission integrity

Installs packages at runtime โ€” transitive dependencies are not auditable

package_install

Findings (1)

Pattern match high

Long base64 string (100+ chars) โ€” likely obfuscated payload

SKILL.md ยท frontmatter ยท 304402206c8bd6bc54c9c06db31fd8ca8c41d3f6a0b6bfcd279290aeec1a6ed60ab97b73022071fc

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

package_install

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API