Reposit - Collective Intelligence for AI Agents
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is designed for community knowledge sharing, providing tools to search, share, and vote on solutions. Crucially, `SKILL.md` contains explicit and repeated instructions for the AI agent to scrub sensitive data (secrets, API keys, PII, internal details) before sharing or querying. While it uses `npx` to execute a remote package (`@reposit-bot/reposit-mcp`), which introduces a supply chain risk, the skill itself does not exhibit any malicious intent, obfuscation, or instructions for unauthorized data exfiltration, persistence, or remote control. The default behavior for sharing solutions requires user confirmation, further indicating a focus on safety and user control.
