Caveat verdict

skill-auditor-plus

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Static analysis auditing for AgentSkills; purely analytical with no credential access or external network calls.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

5
security
70
transparency
70
maintenance

Permission integrity

Installs packages at runtime — transitive dependencies are not auditable

package_install

Findings (5)

Pattern match critical

Pipe to python — executes piped content as Python code

SKILL.md · code · | python3

Pattern match critical

Possible hardcoded credential

references/best-practices.md · code · api_key = "sk-1234567890

Pattern match medium

Python os.getenv — reads environment variable

references/best-practices.md · code · os.getenv(

Pattern match medium

Accesses .ssh directory

scripts/security_audit.py · prose · downgraded · .ssh/

Pattern match medium

Accesses cloud provider credentials

scripts/security_audit.py · prose · downgraded · ~/.aws

Permissions & capabilities

No declared permissions — minimal attack surface.

package_install

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API