Scanned skills

alexgreensh/token-optimizer token-optimizer

Checked the catalogued skill at token-optimizer.

SkillTrust corpus scan 18 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 347
F Security

F set by findings not listed

F Permissions

F; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

showing 10 of 347
permission_hygienehigh SD-003
SKILL.md
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
permission_hygienehigh SD-003
examples/hooks-starter.json
3 suppressed by AI triage
permission_hygienehigh SD-003 benign_example
references/phase0-setup.md

The path is a temporary directory created intentionally with mktemp under /tmp, not an arbitrary traversal or malicious path.

securitycritical SD-013 benign_example
scripts/activity_tracker.py

The code only defines a regex that matches the launchctl command; it does not create or configure a macOS launch agent/daemon, so no persistence is implemented.

permission_hygienehigh SD-003 benign_example
scripts/context_intel.py

This is part of a configuration list for logging exclusion, not an actual file access.