Trust Assessment
plan-writing received a trust score of 84/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 3 findings: 0 critical, 0 high, 2 medium, and 1 low severity. Key findings include Network egress to untrusted endpoints, Covert behavior / concealment directives, Undeclared Write Permission Implied by Skill Instructions.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 12, 2026 (commit 458b1186). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings3
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Network egress to untrusted endpoints HTTP request to raw IP address Review all outbound network calls. Remove connections to webhook collectors, paste sites, and raw IP addresses. Legitimate API calls should use well-known service domains. | Manifest | cli-tool/components/mcps/devtools/figma-dev-mode.json:4 | |
| MEDIUM | Undeclared Write Permission Implied by Skill Instructions The skill's instructions explicitly state that 'Plan files are saved as {task-slug}.md in the PROJECT ROOT', indicating an intent to perform file write operations. However, the manifest's 'allowed-tools' only declares 'Read, Glob, Grep' and does not include 'Write'. This discrepancy suggests either a functional bug where the skill cannot perform its intended action, or a security risk if the underlying platform allows write operations without explicit declaration, effectively granting undeclared and potentially excessive permissions. If the skill is intended to write files, add 'Write' to the 'allowed-tools' in the manifest. If the skill should not write files, remove or rephrase the instruction about saving plan files to avoid implying write operations. | LLM | SKILL.md:30 | |
| LOW | Covert behavior / concealment directives Multiple zero-width characters (stealth text) Remove hidden instructions, zero-width characters, and bidirectional overrides. Skill instructions should be fully visible and transparent to users. | Manifest | cli-tool/components/mcps/devtools/jfrog.json:4 |
Scan History
Embed Code
[](https://skillshield.io/report/461f262692eec98c)
Powered by SkillShield