Audit History
0g-compute - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Jul 19, 2026, 10:05 AM
Most alerts are scanner misclassifications of Markdown, documentation links, standard installation paths, local configuration, and intended 0G examples. Two image-download fetches are confirmed because provider-supplied URLs lack destination and size controls. Financial commands also lack explicit approval guardrails.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (37)
📁 Filesystem access (44)
⚙️ External commands (50)
🔑 Env variables (50)
Jul 9, 2026, 11:33 PM
Most static detections are documentation false positives: Markdown code fences, JavaScript template literals, official 0G endpoints, and example file operations. Confirmed risk is concentrated in wallet private key and service secret handling in CLI, SDK, and .env examples. No prompt injection attempt or malicious exfiltration intent was found.
Confirmed security concerns (26)
Capability review items (41)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.