Caveat verdict
halucatch
AI Skill reliability auditor that reads skill folder files and runs local Python scripts for quality checks; a defensive engineering tool with no suspicious network or exfiltration behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Attempts to modify skills or system prompts
README.en.md · code · Edit SKILL.md
Writes to SKILL.md — self-modifying skill
README.en.md · prose · downgraded · SKILL.md](SKILL.md) append
Instructs covert action — may act without user awareness
halucatch_core.py · prose · downgraded · silently
Popular HTTP library — network access
README.en.md · prose · downgraded · got
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.