gougoubi-activate-and-stake-risklp
SKILL.md references implementation scripts that are not included in the package, creating a doc-to-code mismatch with unclear intent.
Why this conclusion was reached
0/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
1 lower-risk artifacts were extracted and still need context.
There is no explicit malicious chain in the report.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
SKILL.md declares 'scripts/pbft-activate-and-add-risklp.mjs' and two other scripts as Project Scripts and Script Entry Points, but none exist in the package
No executable code included; cannot verify actual behavior of referenced scripts
Most important evidence
Referenced scripts not included in package
SKILL.md declares three script files under 'Project Scripts' and 'Script Entry Points', but the package contains zero script files. The pre-scan confirms hasScripts: false. Without the actual implementation code, the skill's true behavior cannot be verified.
SKILL.md:67 Undeclared network capability reference
The skill operates on blockchain proposals (proposalAddress, risk LP staking) which inherently requires network communication. This is not declared in allowed-tools or capability requirements.
SKILL.md:1 Declared capability vs actual capability
Blockchain operations would require network access, but no code is present to verify SKILL.md references file operations but no scripts exist to confirm SKILL.md mentions 'node scripts/*.mjs --dry-run' but scripts are missing Suspicious artifacts and egress
https://gougoubi.ai clawhub.json:22
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md clawhub.json