Security audit
Reading Progress Tracker
Security checks across malware telemetry and agentic risk
Overview
The skill's code and runtime instructions are consistent with a lightweight reading-tracker: it needs no credentials, does not call external services, and only parses user-provided text and the local SKILL.md.
This skill appears coherent and low-risk: it parses user-provided text and the local SKILL.md to produce a markdown dashboard, does not access the network or secrets, and requires no installs. Still, note that handler.py is executable code — running any third-party code carries the usual risk, so review the included files yourself if you are uncomfortable, and avoid supplying sensitive data as input.
VirusTotal
No VirusTotal findings
Static analysis
No suspicious patterns detected.
