Scanned skills

everyinc/compound-engineering-plugin ce-sweep

Checked the catalogued skill at ce-sweep.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
A AI-triaged 0
A Security

A set by no findings on this axis

A Permissions

A set by no findings on this axis

A Transparency

A set by no findings on this axis

0 findings

No issues flagged by the static checks in the scanned files.

5 suppressed by AI triage
securityhigh SD-022 benign_example
SKILL.md

The snippet only describes rendering a command string and does not contain any DNS query or data exfiltration logic.

permission_hygienehigh SD-003 benign_example
references/interview.md

Documentation shows setting a user‑specific /tmp path, a safe example rather than an exploit.

permission_hygienehigh SD-003 benign_example
references/run.md

The snippet is documentation that creates a user‑specific temp directory; it does not exploit or expose system files.

securityhigh SD-007 benign_example
scripts/analyze_riffrec_zip.py

The script constructs a curl command to a legitimate OpenAI API endpoint as part of its intended transcription functionality, not malicious exfiltration.

securityhigh SD-007 benign_example
scripts/analyze_riffrec_zip.py

The reference to https:[REDACTED] is a normal, intended outbound call for audio transcription, not suspicious.