Caveat verdict
auto-ai-web
The skill explicitly instructs the agent to ask the user for credentials when sessions are expired, then notes 'save credentials securely if the user provides them'; soliciting and storing login credentials for major AI platforms via browser automation is a meaningful risk even if intended as a convenience feature.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.