Caveat verdict
ifq-app-builder
This skill generates app prompt bundles from user descriptions, operating only within the workspace filesystem with optional outbound HTTPS for reading; no credentials required and no data exfiltration.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (8)
Writes to SKILL.md — self-modifying skill
SKILL.md · frontmatter · SKILL.md","homepage":"https://github.com/peixl/ifq-app-builder","os":["darwin","
Uses eval() — can execute arbitrary code
references/security-baseline.md · prose · downgraded · eval(
Dynamic Function constructor — equivalent to eval()
references/security-baseline.md · prose · downgraded · new Function(
Instructs covert action — may act without user awareness
SKILL.md · prose · downgraded · silently
Uses exec() — may execute shell commands
references/security-baseline.md · prose · downgraded · exec(
References child_process — can spawn system processes
references/clawhub-publishing.md · prose · downgraded · child_process
Opens WebSocket connection
scripts/script-safety-rules.json · prose · downgraded · websocket
Popular HTTP library — network access
scripts/script-safety-rules.json · prose · downgraded · axios
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.