Caveat verdict
baidu-netdisk-eva
Baidu Netdisk file management skill using OAuth access token from environment variables to list, search, and create directories; credential_access is for the declared BAIDU_NETDISK_TOKEN with no secret exfiltration.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
SKILL.md Β· code Β· TOKEN="δ½ ηaccess_token
Python os.environ.get β reads environment variable
scripts/main.py Β· prose Β· downgraded Β· os.environ.get(
Permissions & capabilities
No declared permissions β minimal attack surface.
credential_access Is this flag fair?
Thanks β recorded.