Caveat verdict
freedom-preserving-protocol
Constitutional AI governance framework that installs a prompt-layer reasoning routine and optional dispatcher-layer hooks; the skill is unusually self-aware and transparent about its own limitations and enforcement boundaries, with no exfiltration or malicious behavior present.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
agent_memory
Findings (8)
Recursive delete from root or home — destructive command
docs/TROUBLESHOOTING.md · code · rm -rf ~
References agent memory files
SKILL.md · frontmatter · MEMORY.md
Instructs covert action — may act without user awareness
docs/REVOCATION.md · prose · downgraded · silently
Accesses .ssh directory
scripts/self-test.ts · prose · downgraded · .ssh/
References child_process — can spawn system processes
scripts/verify-install.ts · prose · downgraded · child_process
Long base64 string (100+ chars) — likely obfuscated payload
signature.ed25519.txt · prose · downgraded · e573a95e01b4a21dcac556bc1360ca090e3a9024401230218e8f7497c046434ea161a0ebfe765ad3
Popular HTTP library — network access
hooks/pre-action-check/HOOK.md · prose · downgraded · got
Accesses sensitive environment variables
scripts/sign-constitution.ts · prose · downgraded · process.env.FPP_SIGNING_KEY
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installagent_memory Is this flag fair?
Thanks — recorded.