Epistemic Guide

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill's `SKILL.md` explicitly instructs the AI agent to use external tools like 'Web search tools' and 'verify-claims skill' for fact-checking, which is a network-accessing capability. More significantly, it also instructs the agent to use 'Other configured skills or APIs' for verification, even with user consent and transparency. While the stated intent is benign and emphasizes user autonomy and privacy, this broad instruction to invoke potentially any 'other configured skill or API' represents a request for broad permissions. Depending on what other skills are available to the agent, this could lead to unintended actions or exploitation of platform vulnerabilities, even if the user provides general consent for 'verification'. This falls under 'risky capabilities without clear malicious intent' and 'broad permissions'.