Ae1
High
- Category
- analysis-evasion
- Content
`SKILL.md`; do not assume a repository checkout or a user-profile install
- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a GLR command-line helper with disclosed project-scoped operations, and I found no hidden or harmful behavior in the artifacts.
Install this only if you intend to let an agent operate GLR projects and run their configured project roles. Review the project manifest and role commands before use, and set GLR_NO_UPDATE_CHECK=1 if you do not want routine commands to make background release-check requests.
`SKILL.md`; do not assume a repository checkout or a user-profile install
No suspicious patterns detected.