Caveat verdict
digital-product-builder
Enumerates directory contents AND makes external network calls
Builds digital product images using Python Pillow and generates copy via Groq API; the broad capabilities (package_install, dir_traversal, network_out, credential_access) all serve the documented purpose of local image generation and API calls to legitimate services.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Enumerates directory contents AND makes external network calls — filesystem reconnaissance
LLM02 · LLM06 · ASI03
Permission integrity
network_out
package_install
Findings (5)
Accesses process.env — reads environment variables
SKILL.md · code
pip3 install — installs Python packages at runtime
SKILL.md · code · pip3 install
Accesses sensitive environment variables
SKILL.md · code · process.env.GROQ_API_KEY
Node http/https module — low-level network access
SKILL.md · code · require('https')
Python directory traversal
SKILL.md · code · os.walk(
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installdir_traversalnetwork_outcredential_access Thanks — recorded.