Instructions pass high-value credentials through process argv.
Critical
- Code
- suspicious.secret_argv_exposure
- Location
- SKILL.md:132
Security audit
Security checks across malware telemetry and agentic risk
This identity skill is purpose-aligned, but it handles persistent agent identity keys and linking actions with unsafe or under-scoped instructions.
Install only if you are prepared to review or supply the missing scripts yourself. Do not paste real private keys, JWTs, or reusable identity tokens into commands or chat. Treat human-agent linking as a persistent identity action: confirm the DID, challenge, requester, registry destination, and agent name before running it, and configure encryption or a secret store before creating real identities.
65/65 vendors flagged this skill as clean.
Detected: suspicious.secret_argv_exposure