Ae1
- Category
- analysis-evasion
- Content
scripts/query.sh search_resources '{"query":"x402","limit":3}'- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed Sato Hub query integration, but its read-only framing is contradicted by write-capable remote tools and finance-adjacent routing outputs that users should review carefully.
Install only if you are comfortable giving the Sato Hub MCP endpoint access to the queries and routing inputs you provide. Treat swap calldata, launch configs, x402 routing, scaffolded repos, and build plans as advisory only; independently review fees, recipients, source URLs, and generated files before signing, deploying, paying, or submitting anything. Avoid using the write tools unless you intentionally want to create a watch subscription, submit a project, or register an agent passport with Sato Hub.
scripts/query.sh search_resources '{"query":"x402","limit":3}'scripts/query.sh search_resources '{"query":"x402","limit":3}'scripts/query.sh search_resources '{"query":"x402","limit":3}'scripts/query.sh search_resources '{"query":"x402","limit":3}'scripts/query.sh search_resources '{"query":"x402","limit":3}'scripts/query.sh search_resources '{"query":"x402","limit":3}'move; re-run before quoting. Every one of these is read-only: **nothing signs, holds a key, deploys, relays or moves funds.** Each example shows equivalent calls — raw curl (JSON-RPC over the MCP endpoint), the bundled script, and the plain REST route. ## 7. Preflight a repo before you install it
}
mcp_post() {
/usr/bin/env curl -sS --max-time "$TIMEOUT" -X POST "$ENDPOINT" \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
--data "$1"No suspicious patterns detected.