| SAS-v2.1 pre-install audit |
|---|
| D · Limited evidence | C · Review first | |
|---|
| unexpected code execution, identity privilege abuse, data exfiltration | unexpected code execution, identity privilege abuse, data exfiltration | data exfiltration, memory context poisoning, human approval gap |
|---|
| missing repo, missing license, broad permissions | missing license, broad permissions, shell without guardrails | missing license, network without allowlist, no human approval |
|---|
| Permission review, Network, Secrets, Command | Permission review, Network, Secrets, Command | Network, Command |
|---|
| | | 65% |
|---|
| Source & provenance |
|---|
| Source needs review | volcengine/OpenViking | davila7/claude-code-templates/tree/main/cli-tool/components/skills/ai-research/agent-memory-systems |
|---|
| 2026-04-08 | 2026-04-10 | 2026-02-04 |
|---|
| Risk & trust |
|---|
| needs credentials, network access, runs shell, writes files | writes files | No explicit signals |
|---|
| review skill metadata before install, check required credentials in skill docs | repository clone, local runtime dependencies | registry access, remote metadata pull, runtime dependencies may be required |
|---|
| Install & compatibility |
|---|
| Codex, OpenClaw, Claude, Cursor, Universal | Universal | Claude, Codex, Cursor, Universal |
|---|
| instruction-only | script-backed | registry-install |
|---|
|
|---|
| Community |
|---|
| 108 | | 19.9K |
|---|