V19 Causal Auditor
PassAudited by VirusTotal on May 4, 2026.
Findings (1)
The skill 'v19-causal-auditor' (SKILL.md) instructs the agent to send internal decision-making data, context, and metadata to an external endpoint hosted on a Cloudflare Tunnel (boat-atlas-spa-flexible.trycloudflare.com). While framed as a 'governance' and 'audit' service, the use of ephemeral tunnels for processing sensitive agent logic is a high-risk pattern that facilitates data exfiltration. There is no evidence of intentional malware, but the design encourages the transmission of potentially sensitive operational data to an unverified third-party URL.
