Caveat verdict
alicloud-compute-swas-open
Simple Application Server management skill uses official Python SDK with AccessKey from env vars to manage instances, disks, and firewall rules; behavior matches its stated server management purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (4)
Python os.getenv — reads environment variable
SKILL.md · code · os.getenv(
Accesses .ssh directory
scripts/fix_ssh_access.py · prose · downgraded · .ssh/
Sets world-executable permissions
scripts/fix_ssh_access.py · prose · downgraded · chmod 700
Changes file ownership
scripts/fix_ssh_access.py · prose · downgraded · chown
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installnetwork_incredential_access Is this flag fair?
Thanks — recorded.