Security Audit
skypilot-multi-cloud-orchestration
github.com/davila7/claude-code-templatesTrust Assessment
skypilot-multi-cloud-orchestration received a trust score of 90/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 3 findings: 0 critical, 0 high, 1 medium, and 1 low severity. Key findings include Network egress to untrusted endpoints, Covert behavior / concealment directives, Loose Dependency Version Pinning.
The analysis covered 4 layers: dependency_graph, manifest_analysis, llm_behavioral_safety, static_code_analysis. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 11, 2026 (commit 458b1186). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings3
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Network egress to untrusted endpoints HTTP request to raw IP address Review all outbound network calls. Remove connections to webhook collectors, paste sites, and raw IP addresses. Legitimate API calls should use well-known service domains. | Unknown | /var/folders/1k/67b8r20n777f_xcmmm8b7m5h0000gn/T/skillscan-clone-ubxee3w7/repo/cli-tool/components/mcps/devtools/figma-dev-mode.json:4 | |
| LOW | Covert behavior / concealment directives Multiple zero-width characters (stealth text) Remove hidden instructions, zero-width characters, and bidirectional overrides. Skill instructions should be fully visible and transparent to users. | Unknown | /var/folders/1k/67b8r20n777f_xcmmm8b7m5h0000gn/T/skillscan-clone-ubxee3w7/repo/cli-tool/components/mcps/devtools/jfrog.json:4 | |
| INFO | Loose Dependency Version Pinning The skill's manifest specifies a dependency `skypilot>=0.7.0`. While this ensures a minimum version, it allows for automatic updates to any future major, minor, or patch versions. This can introduce unexpected behavior, breaking changes, or even new vulnerabilities if a future version of the dependency has issues. For enhanced security and reproducibility, it is generally recommended to pin dependencies to exact versions (e.g., `skypilot==0.7.0`) or at least to specific minor versions (e.g., `skypilot~=0.7.0`). Pin the `skypilot` dependency to an exact version (e.g., `skypilot==0.7.0`) or a specific minor version (e.g., `skypilot~=0.7.0`) to ensure deterministic builds and prevent unexpected changes from upstream updates. | Unknown | manifest.json:1 |
Scan History
Embed Code
[](https://skillshield.io/report/0aa61451b609d970)
Powered by SkillShield