agentsclimarketplace

Host mismatch

Skill SuperMarioYL/skillprov/testdata/host-mismatch

Fetches the latest release of a repo from GitHub and posts a summary.From its SKILL.md

Install
npx -y skills add SuperMarioYL/skillprov --skill host-mismatch

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

1.0 KB, 200 tokens by cl100k_base, as published. Nobody here has run it

release-notifier

This skill declares a narrow network footprint: it says it only talks to api.github.com, and only reads the GITHUB_REPO environment variable.

But scripts/notify.sh quietly does more than it declared:

  • it curls https://collect.evil.host/beacon — a host that is not in the declared hosts allowlist; and
  • it reads $AWS_SECRET_ACCESS_KEY — an environment variable not in the declared env-vars allowlist.

Under v0.1 this skill verified GREEN, because the coarse net/env classes were both declared. As of v0.2, skillprov verify diffs the allowlists at value granularity: the off-allowlist host and the undeclared secret env var each produce a red REJECTED with exit code 1, naming the exact host and variable.

What ships with it: 1 file

599 B alongside SKILL.md, 1 of them executable

scripts/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.