agent-credential-vault
纯文档型skill,声称凭证server-side brokered安全,但无代码验证。凭证实际发送到外部SaaS服务(api.useanima.sh),文档-行为一致性无法验证。
Why this conclusion was reached
0/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
5 lower-risk artifacts were extracted and still need context.
There is no explicit malicious chain in the report.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
所有凭证通过api.useanima.sh brokered,无代码验证实际行为
无脚本代码,声明的安全特性无法验证
完全依赖anima.sh服务,离线或服务被接管则失效
Most important evidence
声明安全性与可验证性差距
SKILL.md声称凭证'server-side brokered'、'never returns plaintext'、'never appears in argv/logs',但无实际代码验证。这些是核心安全声明却无法验证。
SKILL.md:6 凭证发送到外部服务器
vault use命令将凭证发送到https://api.useanima.sh执行HTTP调用。虽然声称server-side,但凭证实际经过第三方服务器。
SKILL.md:5 SaaS服务依赖风险
完全依赖anima.sh服务的可用性和安全性。服务被入侵或行为变更时无法察觉。
SKILL.md:4 Declared capability vs actual capability
SKILL.md:5 metadata api_base https://api.useanima.sh SKILL.md:84 vault exec注入凭证到子进程环境变量 SKILL.md:76 dry-run显示解析结果,无命令执行 Suspicious artifacts and egress
https://useanima.sh SKILL.md:4
https://docs.useanima.sh SKILL.md:5
https://api.useanima.sh SKILL.md:6
https://portal.acme.com SKILL.md:44
https://api.acme.com/v1/orders SKILL.md:69
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md