Caveat verdict
codesmith
The skill's content appears to be focused on configuration and does not seem to pose any security risks.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
References agent memory files
AGENTS.md ยท code ยท MEMORY.md
Instructs covert action โ may act without user awareness
AGENTS.md ยท prose ยท downgraded ยท silently
Popular HTTP library โ network access
working-patterns.md ยท prose ยท downgraded ยท got
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.