Scanned skills

Goldentrii/AgentRecall-X

Checked the catalogued skill.

SkillTrust corpus scan 22 September 2026 v0.10.0 via ghsearch Verify on GitHub
F AI-triaged 868
F Security

F; retained sample includes a critical finding · SD-002 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

B Transparency

B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →

showing 10 of 868
transparencymedium SD-007
README.full.md
transparencymedium SD-007
README.md
permission_hygienehigh SD-003
UPDATE-LOG.md
permission_hygienehigh SD-003
UPDATE-LOG.md
securitymedium SD-008
UPDATE-LOG.md
securitymedium SD-012
UPDATE-LOG.md
securitycritical SD-002
UPDATE-LOG.md
securityhigh SD-007
UPDATE-LOG.md
permission_hygienehigh SD-003
UPDATE-LOG.md
securityhigh SD-022
contrib/hindsight-cookbook/AGENTRECALL-BACKLOG.md
4 suppressed by AI triage
transparencymedium SD-007 benign_example
README.zh-CN.md

The command is a documentation example, not automatically executed or granted permissions in configuration

permission_hygienehigh SD-003 benign_example
commands/arsave.md

The path is shown in documentation as an example, not an actual file access that could be exploited.

securitymedium SD-008 benign_example
meta/eval/loops/loop-1/results/loop-1-synthesis.md

The flagged line contains a plain executable path, not a base64 string, indicating a false positive.

permission_hygienehigh SD-003 benign_example
scripts/agent-loop/loop-runner.test.mjs

The absolute path appears only in a test case and does not indicate an actual file operation in production.