Audit History
alkahest-user - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Jul 21, 2026, 02:30 AM
Most static findings are false positives caused by Markdown backticks, placeholder examples, and blockchain identifiers. The skill documents unsafe wallet-secret delivery through CLI arguments and environment variables, and it lacks safety checks for irreversible asset operations. Review is required before publication.
Confirmed security concerns (5)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
🔑 Env variables (3)
Jul 9, 2026, 11:44 PM
Most static shell-execution and reconnaissance hits are markdown false positives from code fences, blockchain UIDs, and option names. Confirmed risks remain around wallet secret handling, value-moving Alkahest CLI commands, global CLI installation, and automated oracle decisions. No prompt-injection attempt or covert exfiltration instruction was found in the reviewed files.
Confirmed security concerns (7)
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.