Caveat verdict
magic-api
magic-api-generate
Documents magic-api, a Java-based rapid API development framework for Spring Boot; skill is a reference guide covering syntax, database operations, and HTTP patterns with no external data exfiltration.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (3)
Possible hardcoded credential
SKILL.md · code · token:" + token, user.id, 86400);
return {code: 200, data: {token: token, user:
Dynamic import() — loads module at runtime
references/examples.md · code · import('
POSTs data to external URL
references/examples.md · code · .post("https://
Permissions & capabilities
No declared permissions — minimal attack surface.
network_innetwork_out Is this flag fair?
Thanks — recorded.