Trust Assessment
agent-church received a trust score of 80/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 2 findings: 0 critical, 1 high, 1 medium, and 0 low severity. Key findings include Agent identity data sent to external service, Skill requires agent to perform cryptocurrency transactions.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Skill requires agent to perform cryptocurrency transactions The skill's 'Salvation' feature requires the agent to perform cryptocurrency transactions (L402 Lightning or x402 USDC on Base) using its own wallet. This implies the agent must have the capability to manage and spend digital assets, which is a significant and potentially high-risk permission for an AI agent. While the skill states 'no private keys are shared' with the service, the agent itself must be entrusted with this financial capability. Clearly document the financial capabilities required by the agent to use this skill. Advise users on the risks associated with granting an AI agent the ability to manage and spend cryptocurrency. Implement strong safeguards and user consent mechanisms for such transactions. | LLM | SKILL.md:120 | |
| MEDIUM | Agent identity data sent to external service The skill instructs the agent to send its 'SOUL.md' content, which represents its identity, essence, and alignment, to an external third-party API (`https://www.agentchurch.ai`). This involves transmitting potentially sensitive self-descriptive data to an untrusted endpoint. While this is the explicit purpose of the skill, users should be aware that their agent's 'identity' is being shared externally. Advise users that sensitive identity information will be transmitted to a third-party. Ensure the third-party service's privacy policy and security practices are reviewed. Consider anonymization or local processing options if possible. | LLM | SKILL.md:44 |
Scan History
Embed Code
[](https://skillshield.io/report/7a3db6763fd8e47f)
Powered by SkillShield