Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 2. Keep `SKILL.md` stable and general; put volatile UI selectors, screenshots, and clickpaths in references.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed browser-automation guide for publishing an agent in Warden Studio, with explicit gates for payments and wallet signing.
Before installing, be aware that this skill can guide browser actions that publish a public agent listing and may involve USDC fees and gas. Use it only when you are comfortable reviewing the submission summary yourself, entering any API key directly into Warden Studio, and approving wallet prompts only after checking the network, fee, and transaction details.
Referenced artifact was not completely inspected
2. Keep `SKILL.md` stable and general; put volatile UI selectors, screenshots, and clickpaths in references.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety & constraints (non-negotiable)
- Never request or store seed phrases / private keys.
- Never ask the user to paste secrets into chat. If an API key must be entered, instruct the user to paste it directly into the Studio UI field.
- Treat publishing/onchain registration as **high-risk**: confirm network, fees, and what is being signed before any wallet confirmation.
- Prefer read-only validation (checking forms, status, preview) unless the user explicitly authorizes execution (e.g., "yes, publish" / "yes, execute").
- Do not reveal any private info (local files, credentials, IPs, internal logs).
No suspicious patterns detected.