Caveat verdict
dropspace-content-engine
The skill runs an autonomous social media content pipeline posting to user-configured platforms via the Dropspace API using user-supplied keys; autonomous posting is the explicitly stated and consented purpose, with no unauthorized data flows.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (1)
Possible hardcoded credential
SKILL.md ยท code ยท API_KEY="ds_live_...
Permissions & capabilities
Requires 3 environment variables. (2 sensitive: DROPSPACE_API_KEY, ANTHROPIC_API_KEY).
package_install Is this flag fair?
Thanks โ recorded.