Subscription Box Curator
Security checks across malware telemetry and agentic risk
Overview
The skill is internally consistent with its description: it uses local heuristics to produce markdown subscription-box briefs, includes no external installs or credentials, and the provided code and instructions align with the stated purpose.
This package appears coherent and low-risk: it generates advisory markdown briefs from user-provided prompts using built-in heuristics and requests no credentials or external network access. Before installing, you may want to (1) inspect the full handler.py in your environment to confirm there are no hidden network calls or subprocess executions (the snippet shown was truncated in the prompt but the tests/reference code are local), (2) avoid pasting highly sensitive credentials or proprietary inventory data into prompts, and (3) run the included tests locally to validate behavior. If you need live catalog, inventory, or forecasting integration later, expect to add explicit, audited connectors rather than relying on this skill to access those systems.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
