Caveat verdict
appointment-scheduler
appointment-scheduler-skill
PollyReach API client for outbound phone booking; network_out targets are explicitly declared (api.pollyreach.ai, agent.pollyreach.ai), credential file read/write is limited to its own config path, and behavior matches the stated scheduling purpose.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
References sudo โ requests elevated privileges
SKILL.md ยท frontmatter ยท sudo
Popular HTTP library โ network access
SKILL.md ยท code ยท got
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.