Caveat verdict
perryts
Receives external input AND executes processes
PerryTS native TypeScript compiler guide covering CLI usage, language features, and cross-platform compilation; all installation uses npm/brew/winget package managers with no remote code execution.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Receives external input AND executes processes — the shape of a command & control channel
LLM05 · LLM06 · ASI10
Installs packages AND executes processes — opaque dependency chain with execution
LLM03 · ASI04
Permission integrity
package_install
Findings (7)
Uses eval() — can execute arbitrary code
SKILL.md · prose · downgraded · eval(
Dynamic Function constructor — equivalent to eval()
SKILL.md · prose · downgraded · new Function(
Uses spawn() — can execute external programs
SKILL.md · code · spawn(
Long base64 string (100+ chars) — likely obfuscated payload
SKILL.md · prose · downgraded · variables/functions/classes/enums/interfaces/async/Promise/generators/closures/M
References child_process — can spawn system processes
SKILL.md · prose · downgraded · child_process
Opens WebSocket connection
SKILL.md · prose · downgraded · WebSocket
Popular HTTP library — network access
SKILL.md · prose · downgraded · axios
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installprocess_execnetwork_in Thanks — recorded.