Caveat verdict
skill-sandbox
arc-skill-sandbox
Sandbox tool that runs untrusted skills in an isolated monitored environment and produces a local safety report; all monitoring is local and the honeypot mode injects fake credentials to observe exfiltration attempts rather than exposing real ones.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Reads /proc/self/environ — dumps all environment variables
scripts/sandbox.py · prose · downgraded · /proc/self/environ
Uses exec() — may execute shell commands
scripts/sandbox.py · prose · downgraded · exec(
Python shutil file operation — copies/moves/deletes files
scripts/sandbox.py · prose · downgraded · shutil.rmtree(
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.