Caveat verdict

god-mode-manager

telegrambot

45
๐ŸŸ  Risky
Significant risk patterns flagged โ€” automated deep scan, not behavioral proof.

Slug is telegrambot but the skill is actually God Mode Manager which runs a local file server exposing root path (default C:/) over the network; the capability mismatch between slug and actual function is suspicious even if bound to loopback by default.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

50
security
80
transparency
70
maintenance

Findings (2)

Pattern match critical

Possible hardcoded credential

references/ops.md ยท code ยท TOKEN='change-me-now

Pattern match high

HTTP request to bare IP address โ€” common in malicious payloads

references/ops.md ยท code ยท http://127.0.0.1

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

network_in

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API