Caveat verdict

legado-book-source-developer

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Legado Android app book source development toolkit for creating CSS selector rules to parse authorized websites; the skill explicitly notes use only with user-owned or authorized websites.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
90
transparency
70
maintenance

Findings (6)

Pattern match critical

<script> tag in markdown — potential code injection

references/工具选择决策流程.md · code · <script>

Pattern match high

Base64 decode (atob) — may hide malicious payloads

references/快速写源订阅源原理分析.md · code · atob(

Pattern match high

Data URI with base64 payload — may embed malicious content

references/快速写源订阅源原理分析.md · code · data:text/html;base64,

Pattern match medium

POSTs data to external URL

references/Legado书源开发_长记忆系统.md · code · .post('https://

Pattern match medium

Uses XMLHttpRequest — network access

references/quick_search_url_extractor_使用说明.md · code · XMLHttpRequest

Pattern match medium

Base64 encoding/decoding

references/快速写源订阅源原理分析.md · code · base64Encode

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class B). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

No declared permissions — minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API