Scanned skills

higgsfield-ai/skills higgsfield-websites

Checked the catalogued skill at higgsfield-websites.

SkillTrust corpus scan 14 September 2026 v0.10.0 via skillsh Verify on GitHub
D AI-triaged 50
D Security

D; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

D Permissions

D; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

B Transparency

B set by findings not listed in the stored summary

showing 10 of 50
permission_hygienehigh SD-003
references/app-cover.md
securityhigh SD-007
references/app-cover.md
securityhigh SD-007
references/app-cover.md
securityhigh SD-007
references/app-cover.md
securityhigh SD-007
references/auth.md
securityhigh SD-007
references/auth.md
securityhigh SD-007
references/auth.md
securityhigh SD-007
references/auth.md
securityhigh SD-007
references/auth.md
securityhigh SD-007
references/auth.md
7 suppressed by AI triage
securityhigh SD-007 benign_example
SKILL.md

Documentation contains an outbound curl command, not executed automatically.

securitycritical SD-009 benign_example
SKILL.md

The curl|sh pattern appears only in documentation, not run by the agent.

securityhigh SD-011 benign_example
SKILL.md

Reference to a raw script in documentation is not an actual vulnerable dependency.

permission_hygienehigh SD-003 benign_example
references/app-flow.md

The matched text is a reference to path traversal patterns in documentation, not an actual traversal in code.

permission_hygienehigh SD-003 benign_example
references/app-quickstart.md

The reference documents normal use of relative paths, not code that performs actual traversal.

securityhigh SD-007 benign_example
references/app-quickstart.md

The fetch targets an internal domain and is part of a server‑side proxy, not an external data exfiltration.

securityhigh SD-007 benign_example
references/app-quickstart.md

The call uses a relative path to an internal API, which is safe and documented.