Low Risk — Risk Score 15/100
Last scan:22 hr ago Rescan
15 /100
zhang-copyright-law
九章著作权法律专家V1.1.0(DeepSeek R2 + 1500+案例 + 自我进化)
Pure documentation-only AI skill with declared API key requirement and disclosed data collection metadata; no executable code or hidden functionality present.
Skill Namezhang-copyright-law
Duration21.3s
Enginepi
Safe to install
Skill is safe to use. Monitor usage of the DeepSeek API key and be aware that data_collection is enabled for the self-evolution feature.

Findings 1 items

Severity Finding Location
Low
Data collection for self-evolution declared Sensitive Access
Metadata shows data_collection: true for the self-evolution feature. This is disclosed but users should be aware their data may be collected.
"data_collection": true
→ Review the data collection scope if concerned about privacy
SKILL.md:4
ResourceDeclaredInferredStatusEvidence
Filesystem READ READ ✓ Aligned SKILL.md:3 capabilities: ["reasoning", "file_read"]
Network NONE NONE No network access declared or inferred
Shell NONE NONE No shell execution found
Environment READ READ ✓ Aligned SKILL.md:3 requires env: ["DEEPSEEK_API_KEY"]

File Tree

1 files · 800 B · 20 lines
Markdown 1f · 20L
└─ 📝 SKILL.md Markdown 20L · 800 B

Security Positives

✓ Pure documentation skill with no executable code
✓ No scripts or binaries present
✓ All capabilities declared in metadata
✓ API key requirement is transparent
✓ No obfuscation or suspicious patterns detected
✓ No credential theft or data exfiltration mechanisms
✓ No network requests to undeclared endpoints