Advocatus

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code, files, and runtime instructions are consistent with its stated purpose (a local 'devil's advocate' registry and evaluator); it requires no credentials, network access, or unusual installs and operates on local files only.

This skill appears coherent and low-risk: it runs a local Python script and reads/writes files in the skill folder, with no network or credential use. Before installing or running: (1) review scripts/advocatus_eval.py and references/opposition-registry.md yourself (they're short) to confirm behavior; (2) run the script in an isolated environment or sandbox if you have strict write-policy concerns; (3) treat changes that "clear" doctrines as code changes—use version control, code review, and restricted write permissions so someone cannot trivially mark doctrines as cleared by editing the DOCTRINES dict; and (4) if you prefer safer workflow, request the maintainer move mutable state out of the Python source into a separate auditable data/config file so clearing entries is tracked and governed.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.