| Pre-install decision |
|---|
| 85 · Manual review | 81 · Evidence missing | |
|---|
| Clear source, High execution risk, Universal | Clear source, High execution risk, Universal | Clear source, Low execution risk, Claude |
|---|
| High | High | |
|---|
| unexpected code execution, identity privilege abuse, data exfiltration | prompt injection, tool poisoning, unexpected code execution | data exfiltration, supply chain, human approval gap |
|---|
| missing license, broad permissions, shell without guardrails | missing license, broad permissions, shell without guardrails | missing license, missing install docs, broad permissions |
|---|
| Permission review, Network, Secrets, Command | Permission review, Network, Secrets, Command | Network |
|---|
| 67% | | 60% |
|---|
| Source & provenance |
|---|
| openclaw/skills | neverinfamous/memory-journal-mcp | jinchenma94/bazi-skill |
|---|
| Vertical & Solutions | Knowledge & RAG | Vertical & Solutions |
|---|
|
|---|
| Risk & permission signals |
|---|
| needs credentials, network access, runs shell, writes files | needs credentials, network access | No explicit signals |
|---|
| verify source provenance before install | repository clone, local runtime dependencies | No explicit hints |
|---|
| Install & compatibility |
|---|
| Universal | Universal | Claude Code, Claude |
|---|
| script-backed | script-backed | source-link |
|---|
|
|---|
| Community |
|---|
| 0 | 13 | |
|---|