Advocatus
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, files, and runtime instructions are consistent with its stated purpose (a local 'devil's advocate' registry and evaluator); it requires no credentials, network access, or unusual installs and operates on local files only.
This skill appears coherent and low-risk: it runs a local Python script and reads/writes files in the skill folder, with no network or credential use. Before installing or running: (1) review scripts/advocatus_eval.py and references/opposition-registry.md yourself (they're short) to confirm behavior; (2) run the script in an isolated environment or sandbox if you have strict write-policy concerns; (3) treat changes that "clear" doctrines as code changes—use version control, code review, and restricted write permissions so someone cannot trivially mark doctrines as cleared by editing the DOCTRINES dict; and (4) if you prefer safer workflow, request the maintainer move mutable state out of the Python source into a separate auditable data/config file so clearing entries is tracked and governed.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
