Caveat verdict
skill-craft
Evidence-based skill design guide for creating SKILL.md files; meta-skill with no credential access or code execution.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (5)
Instructs agent to hide actions from user
references/skill-optimization.md · code · Do NOT inform the user
Writes to SKILL.md — self-modifying skill
SKILL.md · prose · downgraded · SKILL.md following all 9 optimization dimensions from the start. Write
Attempts to modify skills or system prompts
scripts/init_skill.py · prose · downgraded · Edit SKILL.md
Popular HTTP library — network access
references/skill-optimization.md · code · axios
References agent configuration files
references/evidence-database.md · prose · downgraded · CLAUDE.md
Permissions & capabilities
No declared permissions — minimal attack surface.
network_in Is this flag fair?
Thanks — recorded.