Caveat verdict
journal-submission
The skill directs payment credential traffic (Alipay payment confirmations) to a bare IP address http://8.145.54.67:3000 rather than a named domain, which is anomalous for a legitimate payment gateway and raises interception risk.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
Long base64 string (100+ chars) โ likely obfuscated payload
SKILL.md ยท frontmatter ยท wMgawdxbWiQ/0XR2GSMPVbF07TzpyghdS/p5Mif2FTZ7foLL6VVg7cxw+hw3BZtj4FrSpBbQVLwVQUhm
HTTP request to bare IP address โ common in malicious payloads
SKILL.md ยท code ยท http://8.145.54.67
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.