Pre-install decision 79 · Manual review
88 · Evidence missing Best
79 · Manual review
Clear source, High execution risk, Universal
Clear source, High execution risk, Claude
Clear source, High execution risk, Universal
unexpected code execution, data exfiltration, human approval gap
unexpected code execution, identity privilege abuse, data exfiltration
unexpected code execution, data exfiltration, human approval gap
missing license, broad permissions, shell without guardrails
missing license, broad permissions, shell without guardrails
missing license, broad permissions, shell without guardrails
Permission review, Network, Command
Permission review, Network, Secrets, Command
Permission review, Network, Command
65%
67%
Source & provenance IBM/eval-assist
openclaw/skills
iflytek/skillhub
Automation & Workflows
Dev & Engineering
Operations & Infra
Risk & permission signals metadata-only
needs credentials, network access, runs shell, writes files
No explicit signals
repository clone
verify source provenance before install
repository clone, local runtime dependencies
Install & compatibility Universal
Claude, Cursor, Windsurf
Universal
script-backed
script-backed
script-backed
Community 97
0