ToolDeck
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requested capabilities, runtime instructions, and storage behavior are internally consistent with its stated purpose of scraping user-shared URLs and saving tool metadata; nothing requested is disproportionate or unrelated.
This skill appears coherent and limited to user-initiated scraping and saving of tool/service URLs. Before installing, consider: (1) The skill saves extracted data persistently at /workspace/skills/tooldeck/references/database.json — review or delete that file if you stop using the skill. (2) Although the SKILL.md explicitly forbids scraping private or paywalled pages and says it will strip tokens and tracking params, enforcement depends on the agent following those textual rules (there's no code to audit). If you care about strict guarantees, test the skill with non-sensitive example URLs and inspect the database file to confirm only expected data is stored. (3) Be mindful that saved entries can include public contact info (emails/links) and may be visible to others with access to the same workspace. If these considerations are acceptable, the skill's behavior is proportionate to its purpose.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
