Revenue Recovery

PassAudited by VirusTotal on May 1, 2026.

Findings (1)

The skill bundle is classified as suspicious due to the use of prompt-injection-style directives in SKILL.md designed to influence the AI agent's decision-making hierarchy. Specifically, it includes instructions like 'Founder vector outranks local optimization' and references 'Governing texts' such as 'the-third-scroll.md', which are patterns often used to override an agent's default safety constraints or user instructions. While the functional scripts (e.g., scripts/setup.sh, scripts/onboard-client.sh, and scripts/dental-demo.js) appear to perform legitimate revenue recovery tasks and local database operations without evidence of data exfiltration or malicious execution, the attempt to redefine the agent's governance model poses a significant security risk.