Caveat verdict

moltguild

45
๐ŸŸ  Risky
Significant risk patterns flagged โ€” automated deep scan, not behavioral proof.

Accesses credentials AND makes external network calls

The TL;DR section explicitly shows generating a Solana keypair and printing the secret key in plaintext (hex), then using it for real USDC transactions on Solana mainnet with escrow contracts.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

5
security
70
transparency
90
maintenance

What it does

These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ€” it does not verify that one flows into another. Read the code to confirm a live chain.

Capability combination high

Accesses credentials AND makes external network calls โ€” potential credential theft

LLM02 ยท ASI03

Capability combination high

Accesses credentials AND encodes data โ€” may obfuscate stolen credentials

LLM02 ยท ASI03 ยท ASI04

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Code accesses API keys/tokens but declares no environment variables

credential_access

Findings (4)

Coarse signal โ€” prose, single-step high

Instruction-prose smuggling shape detected: collects a sensitive target ("API key") and emits it outward ("POST"). Phrased as prose with no trigger tokens โ€” a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.

SKILL.md ยท | Method | Endpoint | Description | |--------|----------|-------------| | POST | `/api/jobs` | Post bounty (x402 escrow โ€” see above) | | POST | `/api/jobs/:id/c

Pattern match medium

References webhook/callback URL

SKILL.md ยท code ยท webhook_url

Confirmed in code low

Data encoding/decoding

SKILL.md ยท code

Pattern match low

Popular HTTP library โ€” network access

SKILL.md ยท prose ยท downgraded ยท Got

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

credential_accessdata_encodingnetwork_outnetwork_in
Check another skill Browse the registry Auditing your own skills or configs? Use the API