makers-deploy
What this skill does
Deployment automation for EdgeOne Makers (Tencent EdgeOne)
github/tencentedgeone - Data Exposure - 2k stars
Threat analysis
Skill info
pkg:github/TencentEdgeOne/edgeone-makers-tools@77de93b?skill=makers-deployAssessments (2)
Data Exposure
Data Exposure via local-llm-review
metadata.yaml
The skill's metadata contains a version number (2.2.0) and author information (edgeone), which could be used to fingerprint the deployment environment if exposed in logs or error messages.Configuration Management
Configuration Management via local-llm-review
references/command-reference.md
The skill stores tokens in `.edgeone/.token` and automatically adds this file to `.gitignore`. While this is a good practice, the documentation does not explicitly warn users about the risks of exposiBadge
Add the Anomity scan badge for makers-deploy to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of makers-deploy? Report an issue or request a rescan.




