Caveat verdict

submit-to-agentbeat

submit-to-agentbeat-2

45
🟠 Risky
Significant risk patterns flagged — automated deep scan, not behavioral proof.

Accesses system credential store AND makes external network calls

Near-identical to submit-to-agentbeat v1.9.0 (this is v1.8.1) with the same EVM private key management and mainnet blockchain transaction scope; the same risk profile applies.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
80
transparency
90
maintenance

What it does

These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.

Capability combination critical

Accesses system credential store AND makes external network calls

LLM02 · ASI03

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Installs packages at runtime — transitive dependencies are not auditable

package_install

Findings (5)

Pattern match high

Data URI with base64 payload — may embed malicious content

reference/erc8004-registration.md · code · data:application/json;base64,

Pattern match medium

Popular HTTP library — network access

SKILL.md · code · axios

Pattern match medium

Base64 encoding/decoding

reference/erc8004-registration.md · code · Base64-encode

Pattern match medium

Accesses system credential store

reference/wallet-setup.md · prose · downgraded · keychain

Pattern match medium

Accesses sensitive environment variables

reference/x402-integration.md · code · process.env.EVM_PRIVATE_KEY

Permissions & capabilities

No declared permissions — minimal attack surface.

credential_storenetwork_innetwork_outpackage_install
Check another skill Browse the registry Auditing your own skills or configs? Use the API