Caveat verdict

evez-mesh-ops

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

This skill is a reference guide consolidating infrastructure operations (Docker, Git, SSH, systemd, etc.) for managing distributed AI gateway meshes; it contains documentation and best-practice commands but no exfiltration, remote code execution, or credential theft.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
100
transparency
90
maintenance

Findings (8)

Pattern match high

Accesses .ssh directory

commands.md · code · .ssh/

Pattern match high

References sudo — requests elevated privileges

commands.md · code · sudo

Pattern match high

Uses eval() — can execute arbitrary code

security.md · prose · downgraded · eval(

Pattern match medium

Accesses OpenClaw config/secrets directly

security.md · prose · downgraded · ~/.openclaw/.env

Pattern match medium

Uses exec() — may execute shell commands

security.md · prose · downgraded · exec (

Pattern match medium

References child_process — can spawn system processes

security.md · prose · downgraded · child_process

Pattern match medium

Accesses system credential store

security.md · prose · downgraded · keychain

Pattern match low

Sets world-executable permissions

SKILL.md · prose · downgraded · chmod 700

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

No declared permissions — minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API