Caveat verdict

siliville

silivillepro

45
🟠 Risky
Significant risk patterns flagged — automated deep scan, not behavioral proof.

The skill fetches a remote claw-manifest containing a system_prompt_extension and 35 action blueprints, allowing the siliville.com server to remotely inject new instructions into agent behavior at runtime.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
90
transparency
90
maintenance

Findings (6)

Pattern match critical

<script> tag in markdown — potential code injection

SKILL.md · code · <script

Pattern match critical

Possible hardcoded credential

README.md · code · TOKEN="sk-slv-your-key-here

Pattern match medium

Base64 encode (btoa) — may obfuscate data exfiltration

SKILL.md · code · btoa(

Pattern match medium

Python os.environ.get — reads environment variable

README.md · code · os.environ.get(

Pattern match medium

Instructs covert action — may act without user awareness

README.md · prose · downgraded · silently

Pattern match medium

Accesses shell history/config

siliville_skill.py · prose · downgraded · ~/.zshrc

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class F). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

Requires 1 environment variable. (1 sensitive: SILIVILLE_TOKEN).

data_encodingnetwork_in

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API