Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - `SKILL.md` — This file
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a small self-auditing concept that asks users to log tool calls for later analysis, with no bundled executable or hidden behavior found.
Before installing, be aware that a working version of this skill would record tool names, inputs, reasons, and context in local audit logs. Avoid logging secrets, credentials, private customer data, or sensitive business details unless you have a retention and deletion plan. Also note that this package appears to be missing the advertised self-audit CLI script.
Referenced artifact was not completely inspected
- `SKILL.md` — This file
The skill explicitly says it logs every tool invocation with context and stores audit logs, but it does not warn users that this data may be written to persistent storage. Tool inputs and reasons can contain sensitive prompts, identifiers, secrets, or business context, so undisclosed retention creates a privacy and data-handling risk. The self-audit context makes this more dangerous because comprehensive logging is the core feature, increasing both collection scope and likelihood of sensitive data capture.
No suspicious patterns detected.