Founder Content
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions generally match a content-creation assistant, but there are ambiguous and potentially privacy-impacting instructions (automatic version-control harvesting and web research) that aren't reflected in declared requirements — ask for clarification before installing.
This skill appears to be a legitimate content-creation workflow, but it is ambiguous about how it performs 'auto mode' collection from version control and how it performs web research. Before installing or enabling autonomous use: 1) Ask the publisher how 'auto mode' obtains commits/PRs — does it require repo read access or tokens, and where would those be stored? 2) Prefer manual mode unless you authorize explicit repository/API access; never grant tokens unless you trust the publisher and understand scope. 3) Be cautious about metrics and concrete numbers — the skill encourages including them, which could expose sensitive business data if fetched automatically. 4) Test the skill with non-sensitive/dummy content first and review any content before posting. 5) If you need stronger assurance, request the publisher add explicit declarations of required config paths/credentials and a clear description of any automated data-collection steps.
Static analysis
Static analysis findings are pending for this release.
VirusTotal
No VirusTotal findings for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
