Tribunal Usage
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle describes 'Tribunal,' a quality enforcement tool that integrates deeply with the development environment by hooking into every file write and test run. While its stated purpose is benign (TDD enforcement and secret scanning), it includes high-risk capabilities such as installing plugin packs from arbitrary remote URLs (e.g., `tribunal install <url>`) and monitoring all agent interactions. These features provide a significant attack surface for remote code execution or data access, although no explicit malicious intent or obfuscation was found in the documentation (SKILL.md).
