Caveat verdict
erlang-distribution
fix-erlang-ssh-cve-erlang-distribution
Receives external input AND executes processes
The skill provides legitimate Erlang distributed systems documentation covering node connectivity, message passing, and clustering patterns using standard BEAM VM primitives, with no evidence of exfiltration or malicious behavior.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Receives external input AND executes processes โ the shape of a command & control channel
LLM05 ยท LLM06 ยท ASI10
Findings (1)
Uses spawn() โ can execute external programs
SKILL.md ยท code ยท spawn(
Permissions & capabilities
No declared permissions โ minimal attack surface.
process_execnetwork_in Thanks โ recorded.