Scanned skills

trailofbits/skills sharp-edges

Checked the catalogued skill at sharp-edges.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 15
F Security

F; retained sample includes a critical finding · SD-013 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a critical finding · SD-004 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

showing 10 of 15
permission_hygienehigh SD-003
references/config-patterns.md
permission_hygienecritical SD-004
references/config-patterns.md
permission_hygienehigh SD-003
references/config-patterns.md
permission_hygienehigh SD-003
references/config-patterns.md
permission_hygienecritical SD-004
references/config-patterns.md
permission_hygienehigh SD-003
references/config-patterns.md
permission_hygienecritical SD-004
references/config-patterns.md
permission_hygienehigh SD-003
references/config-patterns.md
permission_hygienecritical SD-004
references/config-patterns.md
securitycritical SD-013
references/lang-kotlin.md
2 suppressed by AI triage
permission_hygienecritical SD-004 benign_example
references/lang-java.md

The /etc/passwd reference appears only in a comment demonstrating an XXE example, not as executable code that accesses the file.

securitycritical SD-013 benign_example
references/lang-python.md

The matched text refers to shell profile modification, but the actual code is a Python attribute access chain, not a persistence mechanism.