Caveat verdict
security-audit
s3-security-audit
Receives external input AND executes processes
Skill performs security audits using static analysis patterns (grep for SQL injection, XSS, secrets in code) and standard tools like npm audit and pip-audit; all operations are local filesystem scanning with no external data exfiltration.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Receives external input AND executes processes โ the shape of a command & control channel
LLM05 ยท LLM06 ยท ASI10
Installs packages AND executes processes โ opaque dependency chain with execution
LLM03 ยท ASI04
Permission integrity
package_install
Findings (2)
Uses exec() โ may execute shell commands
SKILL.md ยท code ยท exec(
References child_process โ can spawn system processes
SKILL.md ยท code ยท child_process
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_incredential_accesspackage_installfile_readprocess_exec Thanks โ recorded.