complianceradar-ai-monitor
Documentation-only skill with no implementation code but exhibits suspicious branding ('empire-skills') and placeholder API keys that could be mistaken for real configuration.
API_KEY="your-sec-api-key" Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
3 high-risk artifacts or egress signals were extracted.
There is no explicit malicious chain in the report.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
Homepage links to 'github.com/ncreighton/empire-skills' - 'empire' in security context often references post-exploitation frameworks
Lines 116, 119, 132 contain example API keys in configuration format that could be copy-pasted as real credentials
Skill describes capabilities but contains zero scripts or code - cannot verify security claims made in documentation
Claims 'API keys never logged or transmitted' but no code exists to verify this behavior
Most important evidence
Suspicious 'empire-skills' branding
The homepage references 'github.com/ncreighton/empire-skills'. The term 'empire' in security contexts often references post-exploitation frameworks. This branding choice is unusual for a compliance monitoring tool and warrants verification.
SKILL.md:4 Placeholder API keys in example configuration
Lines 116, 119, and 132 contain API key placeholders (e.g., 'your-sec-api-key') in a format that resembles real configuration. While clearly intended as examples, users may copy-paste these as actual credentials.
SKILL.md:116 Unverifiable security claims
The documentation makes security claims ('API keys never logged or transmitted to third parties') without any implementation code to verify. This is classic doc-to-code mismatch - the behavior cannot be audited.
SKILL.md:249 No implementation code present
This SKILL.md describes capabilities but contains zero executable code, scripts, or implementation files. The skill cannot function as documented.
SKILL.md:1 Declared capability vs actual capability
No file operations present - documentation only _meta declares curl/jq binaries but no implementation code exists to verify network calls No shell execution code present _meta declares env vars but no code reads them - can't verify actual usage Suspicious artifacts and egress
API_KEY="your-sec-api-key" SKILL.md:116
API_KEY="your-fda-api-key" SKILL.md:119
API_KEY="your-google-api-key" SKILL.md:132
https://www.sec.gov/cgi-bin/browse-edgar SKILL.md:115
https://open.fda.gov/ SKILL.md:118
https://hooks.slack.com/services/YOUR/WEBHOOK/URL SKILL.md:125
https://www.sec.gov/cgi-bin/browse-edgar. SKILL.md:314
https://api.fda.gov/status.json SKILL.md:320
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md