Book a 30-minute demo →
Skill scan report

csctest1

View on GitHub
18 Low Automated analysis flagged 3 potential risk patterns.

What this skill does

This skill is a tool for creating and packaging other skills. It provides guidance on how to structure and develop skills that extend Claude's capabilities with specialized knowledge, workflows, or to

github/leoyeai - Code Quality/Security - 2.1k stars

ThreatsCode Quality/Security Code Quality

Threat analysis

Code Quality/Security1 finding
Code Quality2 findings

Skill info

Nameleoyeai/csctest1
Registrygithub
Versione5199b5
PURLpkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=csctest1
Stars2.1k

Assessments (3)

Code Quality/Security1 finding MEDIUM
MEDIUM

Code Quality/Security via local-llm-review

scripts/quick_validate.py

The script is incomplete and may not properly validate skill content, potentially allowing malicious or malformed skills to be packaged and used.
Code Quality2 findings LOW
LOW

Code Quality via local-llm-review

scripts/init_skill.py

The template for creating a new skill is incomplete, with placeholder text that may not be properly replaced or validated.
LOW

Code Quality via local-llm-review

scripts/package_skill.py

The script is incomplete and does not show how the packaging process is completed, which could lead to issues with how skills are distributed.

Badge

Add the Anomity scan badge for csctest1 to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/leoyeai/csctest1/)
HTML
<a href="https://anomity.ai/skills/github/leoyeai/csctest1/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of csctest1? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok