This report does not block or authorize the manifest or ZIP.
Static analysis flagged command execution, network, credential, cryptography, and reconnaissance patterns. AI review found the skill is documentation-only, with fenced text diagrams, reference URLs, and safety guidance rather than executable code or secret access. No prompt injection attempt or confirmed malicious behavior was found.
Report position
Historical report
Open audit history before using this report to install.
Audit attestation
Not attestable
The required immutable binding is incomplete.
Human verification
Not verified
No human verification is recorded for this report.
Coverage
1 Files scanned · 249 Lines analyzed
1 item shown for review
Limitations
This report does not claim runtime or sandbox execution and does not prove the absence of side effects.
01
Evidence chain
Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.
The skill discusses autonomous crypto business development, paid data calls, x402 micropayments, and wallet separation. This is legitimate guidance, but users should apply human approval and verified endpoints before spending funds or contacting projects.
The operational risk is explicit because the documentation covers paid API calls and wallet workflows. The risk is limited because the skill is not executable code.
04
Expert evidence
Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.
Artifact subject
Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable
Analysis metadata
Audit model: codex
Analysis state: Complete
Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.
The Ruby or shell backtick detections map to Markdown fenced text diagrams and flow descriptions. No executable command, shell invocation, or user-controlled command construction is present.
The referenced lines are Markdown code fences labeled text. They describe architecture and model routing, not shell execution.
The hardcoded URL findings are GitHub reference links to an implementation. The skill does not contain code that sends requests, uploads data, or contacts those URLs automatically.
Both locations are plain documentation references. No network API call or data transfer logic exists in the scanned file.
The private key finding appears in a security rule telling users never to share API keys or wallet private keys. It does not request secrets, read secrets, or instruct exfiltration.
The exact context is a prohibition on sharing secrets. This is safety guidance rather than credential access.
The weak cryptographic algorithm findings appear to be triggered by crypto-domain vocabulary and agent registration text. No hash algorithm, cipher selection, key derivation, or custom cryptographic implementation is described.
The cited lines discuss cryptocurrency business workflows and agent metadata. No weak algorithm such as MD5, SHA1, DES, or RC4 is present.
System Reconnaissance Findings Are Business Workflow Terms
The reconnaissance findings refer to intelligence sources, ROI tracking, deployer fund analysis, and paid API logging. They do not enumerate the host system, collect local environment data, or run discovery commands.
The text concerns crypto market research and audit logging. It does not contain host reconnaissance commands or local system inspection logic.
The dangerous combination of execution, network access, and credential access was not confirmed. The file contains documentation, reference URLs, and defensive key-handling guidance, with no runnable code path connecting them.
Each component of the heuristic resolves to non-executable documentation. No semantic evidence shows malicious chaining or exfiltration intent.