This report does not block or authorize the manifest or ZIP.
The skill is a LabArchives API integration package with expected network calls, local backup/configuration writes, and documented shell setup commands. The critical ransomware and C2 signals are false positives from prior audit text and documentation, but users should treat API credentials and notebook backups as sensitive data.
Report position
Historical report
Open audit history before using this report to install.
Audit attestation
Not attestable
The required immutable binding is incomplete.
Human verification
Not verified
No human verification is recorded for this report.
Coverage
8 Files scanned · 2,419 Lines analyzed
16 items shown for review
Limitations
This report does not claim runtime or sandbox execution and does not prove the absence of side effects.
01
Evidence chain
Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.
The skill writes backup or configuration files to local paths. This is expected behavior, but it can create sensitive files that require careful storage.
The skill writes backup or configuration files to local paths. This is expected behavior, but it can create sensitive files that require careful storage.
The skill writes backup or configuration files to local paths. This is expected behavior, but it can create sensitive files that require careful storage.
The SKILL.md example instructs users to run local shell commands. They are visible setup or utility commands rather than hidden execution, but install and script execution require user trust.
The SKILL.md example instructs users to run local shell commands. They are visible setup or utility commands rather than hidden execution, but install and script execution require user trust.
The SKILL.md example instructs users to run local shell commands. They are visible setup or utility commands rather than hidden execution, but install and script execution require user trust.
The SKILL.md example instructs users to run local shell commands. They are visible setup or utility commands rather than hidden execution, but install and script execution require user trust.
The SKILL.md example instructs users to run local shell commands. They are visible setup or utility commands rather than hidden execution, but install and script execution require user trust.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
This documents or performs HTTP requests to LabArchives or OAuth endpoints. The network access is expected for the skill, but users should verify endpoints and credentials before use.
03
Risk findings
Confirmed security concerns are separated from items that still need review.
No confirmed security findings were recorded for this completed audit.
04
Remediation
Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.
FIX-001
Medium
The skill writes configuration and backup files that may contain sensitive research data or credentials.
Keep default file permissions restrictive, document safe output directories, and remind users not to commit generated files.
FIX-002
Medium
The skill asks users to run local scripts and install a third-party LabArchives wrapper.
Recommend reviewing scripts and dependency sources before execution, especially in regulated research environments.
FIX-003
Low
Examples include disabling SSL certificate verification for testing.
Clearly mark verify=False examples as non-production only and recommend certificate installation for institutional proxies.
05
Expert evidence
Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.
Artifact subject
Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable
Analysis metadata
Audit model: claude
Analysis state: Complete
Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.