Caveat verdict
semantic-search
Enterprise semantic search connecting to user-configured internal database endpoints via environment variables; all API calls go to user-controlled infrastructure.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (3)
Possible hardcoded credential
SKILL.md · code · PASSWORD="your_password
HTTP request to bare IP address — common in malicious payloads
PROJECT_CONFIG.md · code · http://192.168.0.14
Python os.getenv — reads environment variable
CONFIG_GUIDE.md · code · os.getenv(
Permissions & capabilities
Requires 4 environment variables. (1 sensitive: FLIGHT_DB_PASSWORD). Requires 1 system binary.
package_installnetwork_in Is this flag fair?
Thanks — recorded.