Caveat verdict

Agent-to-Owner File Bridge

file-links-tool

88
๐ŸŸข Trusted
No high-risk patterns surfaced by the deep scan โ€” automated capability review, not behavioral proof.

Agent-to-owner file sharing bridge where every sensitive action requires explicit user confirmation before execution; the server code is open-source and self-hosted with no silent operations.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

60
security
100
transparency
90
maintenance

Findings (2)

Pattern match critical

Possible hardcoded credential

SKILL.md ยท frontmatter ยท API_KEY: "Secret key for authenticating with the bridge server. In Manual Mode:

Pattern match medium

References tunneling service

SKILL.md ยท frontmatter ยท localtunnel

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API