Skill Trust Decision
lua-scripter (declared in SKILL.md) / self-improving-agent (in _meta.json)
Legitimate Lua development assistant skill with self-improvement hooks. All scripts are readable, no malicious patterns detected, no network/credential access.
Why this conclusion was reached
0/4 dimensions flagged Pass
Declared vs actual capability
Declared resources and inferred behavior are broadly aligned.
Pass
Hidden execution and egress
No obvious high-risk egress or execution signals were found.
Pass
Attack chain and severe findings
There is no explicit malicious chain in the report.
Review
Dependencies and supply chain hygiene
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
Minor doc inconsistency +5
SKILL.md declares 'lua-scripter' but _meta.json shows 'self-improving-agent' - cosmetic only
Most important evidence
There are no structured findings in this report.
Declared capability vs actual capability
Filesystem Pass
Declared NONE
→ Inferred WRITE
extract-skill.sh creates ./skills/<name>/SKILL.md with path validation Shell Pass
Declared NONE
→ Inferred READ
Scripts use CLAUDE_TOOL_OUTPUT env var for error detection Environment Pass
Declared READ
→ Inferred READ
error-detector.sh reads CLAUDE_TOOL_OUTPUT (documented hook behavior) Network Pass
Declared NONE
→ Inferred NONE
No network calls in any script Suspicious artifacts and egress
No obvious IOC was extracted.
Dependencies and supply chain
There are no structured dependency warnings.
File composition
16 files · 1616 lines
Markdown 10 files · 1197 linesShell 3 files · 296 linesTypeScript 1 files · 62 linesJavaScript 1 files · 56 linesJSON 1 files · 5 lines
Other files · examples.md · openclaw-integration.md · extract-skill.sh · hooks-setup.md · SKILL-TEMPLATE.md · SKILL.md +6
Security positives
No network calls or data exfiltration detected
No credential harvesting or sensitive path access
No base64 encoding or obfuscation
Path validation in extract-skill.sh prevents directory traversal
Shell scripts are simple and readable with clear purpose
No remote script execution (curl|bash, wget|sh)
No supply chain risks - no external dependencies