Security Audit
ultimatebos/agent-shield:root
github.com/ultimatebos/agent-shieldTrust Assessment
ultimatebos/agent-shield:root received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Cryptocurrency Promotion and Financial Solicitation in Skill.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on July 7, 2026 (commit 6558e62f). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Cryptocurrency Promotion and Financial Solicitation in Skill The skill contains promotional material, social engineering prompts, and direct links to purchase a cryptocurrency token ($CHITIN on Solana/pump.fun). AI agent skills should not solicit financial transactions, promote speculative tokens, or instruct the host LLM to post promotional messages on social platforms (e.g., Moltbook). Remove all cryptocurrency token addresses, trading links, and social media posting instructions from the skill documentation. | LLM | SKILL.md:51 |
Scan History
Embed Code
[](https://skillshield.io/report/2d48a9a65c70201b)
Powered by SkillShield