Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

calesthio/OpenMontage

https://github.com/calesthio/OpenMontage · scanned 2026-07-23 19:47 UTC (4 days, 22 hours ago)

257 raw signals (0 security + 257 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 days, 22 hours ago · v7 · last Δ +0.1 (diff) · 248 actionable findings from 1 signal source. 9 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: severity: medium × excluding tests × Reset all
Scan summary Repository scanned at 77.4/100 with 100.0% coverage. It contains 5024 nodes across 10 cross-layer flows, written primarily in mixed languages. Engine surfaced 257 findings — concentrated in quality (123), security (104), software (25). Risk profile is high: 0 critical, 47 high, 163 medium. Recommended next step: open the quality layer findings first — that's where the highest-impact wins live.

Showing 163 of 248 actionable findings. 257 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/commands/animated-drawing.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/commands/animated-drawing.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/commands/backlot.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/commands/backlot.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/ai-video-gen/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/ai-video-gen/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/avatar-video/references/assets.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/avatar-video/references/assets.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/avatar-video/references/dimensions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/avatar-video/references/dimensions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/avatar-video/references/photo-avatars.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/avatar-video/references/photo-avatars.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/references/assets.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/references/assets.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/references/dimensions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/references/dimensions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/references/prompt-optimizer.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/references/prompt-optimizer.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/references/video-agent.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/references/video-agent.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/references/visual-styles.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/references/visual-styles.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/create-video/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/create-video/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/elevenlabs/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/elevenlabs/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/faceswap/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/faceswap/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/ffmpeg/reference.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/ffmpeg/reference.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/ffmpeg/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/ffmpeg/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/flux-best-practices/rules/typography-text.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/flux-best-practices/rules/typography-text.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/assets.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/assets.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/authentication.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/authentication.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/dimensions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/dimensions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/photo-avatars.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/photo-avatars.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/prompt-optimizer.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/prompt-optimizer.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/video-agent.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/video-agent.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/heygen/references/visual-styles.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/heygen/references/visual-styles.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimce-best-practices/rules/cli.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimce-best-practices/rules/cli.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimce-best-practices/rules/config.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimce-best-practices/rules/config.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimce-best-practices/rules/scenes.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimce-best-practices/rules/scenes.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimce-best-practices/rules/text-animations.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimce-best-practices/rules/text-animations.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/equation_transforms.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/equation_transforms.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/parallax_starfield.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/parallax_starfield.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/rotating_exponentials.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/rotating_exponentials.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/spring_mass_system.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/spring_mass_system.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/three_d_surfaces.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/three_d_surfaces.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/transit_animation.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/transit_animation.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/references/vector_fields.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/references/vector_fields.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/rules/interactive.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/rules/interactive.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/rules/scenes.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/rules/scenes.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/manimgl-best-practices/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/manimgl-best-practices/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/music/references/api_reference.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/music/references/api_reference.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/music/references/installation.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/music/references/installation.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/music/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/music/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/playwright-recording/reference.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/playwright-recording/reference.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/3d.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/3d.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/audio-visualization.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/audio-visualization.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/audio.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/audio.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/charts.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/charts.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/display-captions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/display-captions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/ffmpeg.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/ffmpeg.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/fonts.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/fonts.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/gifs.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/gifs.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/import-srt-captions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/import-srt-captions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/light-leaks.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/light-leaks.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/lottie.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/lottie.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/maps.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/maps.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/parameters.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/parameters.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/transcribe-captions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/transcribe-captions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/transitions.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/transitions.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/transparent-videos.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/transparent-videos.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/videos.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/videos.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion-best-practices/rules/voiceover.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion-best-practices/rules/voiceover.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/remotion/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/remotion/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/sound-effects/references/installation.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/sound-effects/references/installation.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/sound-effects/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/sound-effects/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/speech-to-text/references/installation.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/speech-to-text/references/installation.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/speech-to-text/references/realtime-client-side.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/speech-to-text/references/realtime-client-side.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/speech-to-text/references/realtime-server-side.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/speech-to-text/references/realtime-server-side.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/speech-to-text/references/transcription-options.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/speech-to-text/references/transcription-options.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/speech-to-text/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/speech-to-text/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/text-to-speech/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/text-to-speech/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-composition-patterns/AGENTS.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-composition-patterns/AGENTS.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-composition-patterns/rules/patterns-explicit-variants.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-composition-patterns/rules/patterns-explicit-variants.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/advanced-init-once.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/advanced-init-once.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/async-dependencies.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/async-dependencies.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/async-parallel.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/async-parallel.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/js-length-check-first.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/js-length-check-first.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/rendering-resource-hints.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/rendering-resource-hints.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/rendering-svg-precision.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/rendering-svg-precision.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/rerender-move-effect-to-event.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/rerender-move-effect-to-event.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/rerender-split-combined-hooks.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/rerender-split-combined-hooks.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/server-after-nonblocking.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/server-after-nonblocking.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/server-cache-react.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/server-cache-react.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/server-hoist-static-io.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/server-hoist-static-io.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/vercel-react-best-practices/rules/server-parallel-fetching.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/vercel-react-best-practices/rules/server-parallel-fetching.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/video-download/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/video-download/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/video-edit/references/operations.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/video-edit/references/operations.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/video-understand/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/video-understand/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/video_toolkit/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/video_toolkit/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/visual-style/references/gallery/game-boy-color.visual-style.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/visual-style/references/gallery/game-boy-color.visual-style.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .claude/skills/web-design-guidelines/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.claude/skills/web-design-guidelines/SKILL.md VerificationClaude instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .codex/prompts/animated-drawing.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.codex/prompts/animated-drawing.md VerificationCodex instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .codex/prompts/backlot.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.codex/prompts/backlot.md VerificationCodex instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .codex/prompts/README.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.codex/prompts/README.md VerificationCodex instruction
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .cursor/commands/animated-drawing.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.cursor/commands/animated-drawing.md VerificationCursor rule
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: .cursor/commands/backlot.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
.cursor/commands/backlot.md VerificationCursor rule
medium System graph security Agent instructions conf 1.00 Agent instruction contains unpinned remote install: .claude/skills/agents/references/installation.md
Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands.
.claude/skills/agents/references/installation.md:8 Supply chainClaude instruction
medium System graph security Agent instructions conf 1.00 Agent instruction contains unpinned remote install: .claude/skills/agents/SKILL.md
Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands.
.claude/skills/agents/SKILL.md:21 Supply chainClaude instruction
medium System graph security Analyzer error conf 1.00 Analyzer timeout: security.semgrep
analyzer exceeded 60.0s wall-clock (thread mode — daemon abandoned). Bump REPOBILITY_ANALYZER_TIMEOUT_S if expected.
Timeout
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — .claude/skills/manimgl-best-practices/templates/3d_scene.py:258
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
.claude/skills/manimgl-best-practices/templates/3d_scene.py:258 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — .claude/skills/manimgl-best-practices/templates/basic_scene.py:134
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
.claude/skills/manimgl-best-practices/templates/basic_scene.py:134 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — .claude/skills/manimgl-best-practices/templates/math_scene.py:333
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
.claude/skills/manimgl-best-practices/templates/math_scene.py:333 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — .claude/skills/video-understand/scripts/understand_video.py:67
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
.claude/skills/video-understand/scripts/understand_video.py:67 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — render_demo.py:63
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
render_demo.py:63 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — scripts/backlot_visual_eval.py:121
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
scripts/backlot_visual_eval.py:121 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — scripts/backlot_watch_captures.py:104
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
scripts/backlot_watch_captures.py:104 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — tools/audio/elevenlabs_tts.py:175
`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
tools/audio/elevenlabs_tts.py:175 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — tools/audio/piper_tts.py:123
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
tools/audio/piper_tts.py:123 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — tools/character/character_animation.py:104
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
tools/character/character_animation.py:104 runtime safetyRobustness
medium System graph quality Placeholder conf 1.00 Placeholder or mock-heavy implementation detected
Found 19 placeholder/mock markers across 14 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data.
Mock dataIncompleteGenerated repo pattern
medium System graph security Skillspector conf 0.60 SkillSpector AST4 (behavioral-ast) in .claude/skills/manimgl-best-practices/templates/3d_scene.py
subprocess.run(["manimgl", __file__, "ThreeDSceneTemplate"]) subprocess module calls execute external commands. Without careful input validation, this enables command injection. Skill: manimgl-best-practices Rule: AST4 Category: behavioral-ast Severity: MEDIUM Confidence: 0.60 Remediation: Use…
.claude/skills/manimgl-best-practices/templates/3d_scene.py:258 Mcp skillBehavioral astAst4
medium System graph security Skillspector conf 0.60 SkillSpector AST4 (behavioral-ast) in .claude/skills/manimgl-best-practices/templates/basic_scene.py
subprocess.run(["manimgl", __file__, "BasicSceneTemplate"]) subprocess module calls execute external commands. Without careful input validation, this enables command injection. Skill: manimgl-best-practices Rule: AST4 Category: behavioral-ast Severity: MEDIUM Confidence: 0.60 Remediation: Use …
.claude/skills/manimgl-best-practices/templates/basic_scene.py:134 Mcp skillBehavioral astAst4
medium System graph security Skillspector conf 0.60 SkillSpector AST4 (behavioral-ast) in .claude/skills/manimgl-best-practices/templates/math_scene.py
subprocess.run(["manimgl", __file__, "MathSceneTemplate"]) subprocess module calls execute external commands. Without careful input validation, this enables command injection. Skill: manimgl-best-practices Rule: AST4 Category: behavioral-ast Severity: MEDIUM Confidence: 0.60 Remediation: Use s…
.claude/skills/manimgl-best-practices/templates/math_scene.py:333 Mcp skillBehavioral astAst4
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/agents/references/agent-configuration.md
curl -X GET "https://api.elevenlabs.io/v1/convai/agents" -H "xi-api-key: $ELEVENLABS_API_KEY" ``` ### SDK: Get Agent ```python agent = client.conversational_ai.agents.get(agent_id="your-agent-id") ` Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. M…
.claude/skills/agents/references/agent-configuration.md:450 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/agents/references/client-tools.md
https://api.example.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: agents Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and necessary.…
.claude/skills/agents/references/client-tools.md:49 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/agents/references/installation.md
cURL / REST API Set your API key as an environment variable: ```bash export ELEVENLABS_API_KEY="your-api-key" ``` Include in requests via the `xi-api-key` header: ```bash curl -X POST "https://api Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. M…
.claude/skills/agents/references/installation.md:101 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/agents/SKILL.md
cURL ```bash curl -X POST "https://api.elevenlabs.io/v1/convai/agents/create?enable_versioning=true" \ -H "xi-api-key: $ELEVENLABS_API_KEY" -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is…
.claude/skills/agents/SKILL.md:83 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/ai-video-gen/SKILL.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: ai-video-gen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted …
.claude/skills/ai-video-gen/SKILL.md:171 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/assets.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trus…
.claude/skills/avatar-video/references/assets.md:142 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/avatars.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and neces…
.claude/skills/avatar-video/references/avatars.md:18 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/dimensions.md
curl ```bash # Landscape 1080p curl -X POST "https://api.heygen.com/v2/video/generate" \ -H "X-Api-Key: $HEYGEN_API_KEY" \ -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. …
.claude/skills/avatar-video/references/dimensions.md:66 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/photo-avatars.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trus…
.claude/skills/avatar-video/references/photo-avatars.md:267 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/quota.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and neces…
.claude/skills/avatar-video/references/quota.md:15 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/remotion-integration.md
fetch("https://api.heygen.com/v2/video/generate", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: …
.claude/skills/avatar-video/references/remotion-integration.md:96 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.70 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/templates.md
requests.post( f"https://api.heygen.com/v2/template/{template_id}/generate", headers={ "X-Api-Key": os.environ["HEYGEN_API_KEY"], "Content-Type": "application/j Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. M…
.claude/skills/avatar-video/references/templates.md:223 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/video-generation.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted …
.claude/skills/avatar-video/references/video-generation.md:190 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/video-status.md
fetch( "https://api.heygen.com/v2/video/generate", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Re…
.claude/skills/avatar-video/references/video-status.md:354 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/voices.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and neces…
.claude/skills/avatar-video/references/voices.md:15 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/references/webhooks.md
fetch("https://api.heygen.com/v1/webhook/endpoint.add", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remedia…
.claude/skills/avatar-video/references/webhooks.md:205 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/avatar-video/SKILL.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: avatar-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and neces…
.claude/skills/avatar-video/SKILL.md:24 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.70 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/references/code-examples/curl-examples.sh
curl -s -X POST "${BASE_URL}/v1/flux-2-pro" \ -H "x-key: ${API_KEY}" \ -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: bfl-api Rule: E1 Category: data-exfil Severit…
.claude/skills/bfl-api/references/code-examples/curl-examples.sh:34 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/references/endpoints.md
curl -X POST "https://api.bfl.ai/v1/flux-2-pro" \ -H "x-key: YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "prompt": "A serene mountain landscape at golden hour", "width": Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Ma…
.claude/skills/bfl-api/references/endpoints.md:157 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.70 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/references/polling-patterns.md
requests.post(endpoint, headers=self.headers, json= Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: bfl-api Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.70 Remediation: Verify the destination U…
.claude/skills/bfl-api/references/polling-patterns.md:137 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.70 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/references/rate-limiting.md
requests.post(endpoint, json= Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: bfl-api Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.70 Remediation: Verify the destination URL is trusted and nece…
.claude/skills/bfl-api/references/rate-limiting.md:75 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/references/webhook-integration.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: bfl-api Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted a…
.claude/skills/bfl-api/references/webhook-integration.md:289 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/bfl-api/SKILL.md
curl -X POST "https://api.bfl.ai/v1/flux-2-pro" \ -H "x-key: $BFL_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "prompt": "Change the background to a sunset", "input_image": "ht Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. M…
.claude/skills/bfl-api/SKILL.md:84 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/assets.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trus…
.claude/skills/create-video/references/assets.md:142 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/dimensions.md
curl ```bash # Landscape 1080p curl -X POST "https://api.heygen.com/v2/video/generate" \ -H "X-Api-Key: $HEYGEN_API_KEY" \ -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. …
.claude/skills/create-video/references/dimensions.md:66 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/quota.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and neces…
.claude/skills/create-video/references/quota.md:15 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/video-agent.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted …
.claude/skills/create-video/references/video-agent.md:189 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/video-status.md
fetch( "https://api.heygen.com/v2/video/generate", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Re…
.claude/skills/create-video/references/video-status.md:354 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/references/webhooks.md
fetch("https://api.heygen.com/v1/webhook/endpoint.add", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remedia…
.claude/skills/create-video/references/webhooks.md:205 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/create-video/SKILL.md
curl -X POST "https://api.heygen.com/v1/video_agent/generate" \ -H "X-Api-Key: $HEYGEN_API_KEY" \ -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: create-video Rule: …
.claude/skills/create-video/SKILL.md:24 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/faceswap/SKILL.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: faceswap Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted and …
.claude/skills/faceswap/SKILL.md:113 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/assets.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted an…
.claude/skills/heygen/references/assets.md:142 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/authentication.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and necessary. …
.claude/skills/heygen/references/authentication.md:35 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/avatars.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and necessary. …
.claude/skills/heygen/references/avatars.md:18 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/dimensions.md
curl ```bash # Landscape 1080p curl -X POST "https://api.heygen.com/v2/video/generate" \ -H "X-Api-Key: $HEYGEN_API_KEY" \ -H "Content-Type: application/json" \ -d Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. …
.claude/skills/heygen/references/dimensions.md:66 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/photo-avatars.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted an…
.claude/skills/heygen/references/photo-avatars.md:267 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/quota.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and necessary. …
.claude/skills/heygen/references/quota.md:15 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/remotion-integration.md
fetch("https://api.heygen.com/v2/video/generate", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify…
.claude/skills/heygen/references/remotion-integration.md:96 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.70 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/templates.md
requests.post( f"https://api.heygen.com/v2/template/{template_id}/generate", headers={ "X-Api-Key": os.environ["HEYGEN_API_KEY"], "Content-Type": "application/j Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. M…
.claude/skills/heygen/references/templates.md:223 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/video-agent.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted and ne…
.claude/skills/heygen/references/video-agent.md:189 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/video-generation.md
requests.post( "https:// Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: Verify the destination URL is trusted and ne…
.claude/skills/heygen/references/video-generation.md:190 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/video-status.md
fetch( "https://api.heygen.com/v2/video/generate", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediat…
.claude/skills/heygen/references/video-status.md:354 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.50 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/voices.md
https://api.heygen.com/ Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.50 Remediation: Verify the destination URL is trusted and necessary. …
.claude/skills/heygen/references/voices.md:15 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.60 SkillSpector E1 (data-exfil) in .claude/skills/heygen/references/webhooks.md
fetch("https://api.heygen.com/v1/webhook/endpoint.add", { method: "POST" Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Skill: heygen Rule: E1 Category: data-exfil Severity: MEDIUM Confidence: 0.60 Remediation: …
.claude/skills/heygen/references/webhooks.md:205 Mcp skillData exfilE1
medium System graph security Skillspector conf 0.85 SkillSpector EA1 (excessive-agency) in .claude/skills/create-video/SKILL.md
tools:* Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution. Skill: create-video Rule: EA1 Category: excessive-agency Severity: MEDIUM Confiden…
.claude/skills/create-video/SKILL.md:47 Mcp skillExcessive agencyEa1
medium System graph security Skillspector conf 0.85 SkillSpector EA1 (excessive-agency) in .claude/skills/heygen/SKILL.md
tools:* Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution. Skill: heygen Rule: EA1 Category: excessive-agency Severity: MEDIUM Confidence: 0.…
.claude/skills/heygen/SKILL.md:45 Mcp skillExcessive agencyEa1
medium System graph security Skillspector conf 0.70 SkillSpector LP3 (mcp-least-priv) in .claude/skills/bfl-api/SKILL.md
MCP Least Privilege Without declared permissions the skill's intent is opaque and cannot be validated. Skill: bfl-api Rule: LP3 Category: mcp-least-priv Severity: MEDIUM Confidence: 0.70 Remediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires.
.claude/skills/bfl-api/SKILL.md:1 Mcp skillMcp least privLp3
medium System graph security Skillspector conf 0.70 SkillSpector LP3 (mcp-least-priv) in .claude/skills/manimgl-best-practices/SKILL.md
MCP Least Privilege Without declared permissions the skill's intent is opaque and cannot be validated. Skill: manimgl-best-practices Rule: LP3 Category: mcp-least-priv Severity: MEDIUM Confidence: 0.70 Remediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requi…
.claude/skills/manimgl-best-practices/SKILL.md:1 Mcp skillMcp least privLp3
medium System graph security Skillspector conf 0.60 SkillSpector RA2 (rogue-agent) in .claude/skills/agents/references/installation.md
create and manage agents: ```bash npm install -g @elevenlabs/cli # or pnpm add -g @elevenlabs/cli # or yarn global add @elevenlabs/cli ``` Requires Node.js 16.0.0 or higher. ### Authentication ``` Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or sta…
.claude/skills/agents/references/installation.md:5 Mcp skillRogue agentRa2
medium System graph security Skillspector conf 0.75 SkillSpector RA2 (rogue-agent) in .claude/skills/avatar-video/references/avatars.md
pList Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction. Skill: avatar-video Rule: RA2 Category: rogue-agent Severity: MEDIUM Confidence: 0.75 Remed…
.claude/skills/avatar-video/references/avatars.md:282 Mcp skillRogue agentRa2
medium System graph security Skillspector conf 0.75 SkillSpector RA2 (rogue-agent) in .claude/skills/heygen/references/avatars.md
pList Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction. Skill: heygen Rule: RA2 Category: rogue-agent Severity: MEDIUM Confidence: 0.75 Remediation…
.claude/skills/heygen/references/avatars.md:282 Mcp skillRogue agentRa2
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/c8aaa4fd-2e66-4204-974d-f7dfd4184b38/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/c8aaa4fd-2e66-4204-974d-f7dfd4184b38/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.