warden

Warn

Audited by Runlayer on Feb 22, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
5
Flagged
5
Chunks
5
Flagged Files (5)
references/cli-reference.mdHIGH
78.3%

Malicious tool definition detected

| Option | Description | |--------|-------------| | `--remote <ref>` | Specific remote to sync (default: all) | **Setup-app:** | Option | Description | |--------|-------------| | `--org <name>` | Create under organization (default: personal) | | `--port <number>` | Local server port (default: 3000) | | `--timeout <sec>` | Callback timeout in seconds (default: 300) | | `--name <string>` | Custom app name (default: Warden) | | `--no-open` | Print URL instead of opening browser | ## Severity Levels

references/configuration.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/configuration.md Description: # Configuration (warden.toml) See [config-schema.md](config-schema.md) for the complete schema reference.

references/creating-skills.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/creating-skills.md Description: # Creating Skills Skills are markdown files that tell Warden what to look for.

SKILL.mdHIGH
72.6%

Malicious tool definition detected

Commit the changes Run Warden once to validate work. Do not loop re-running Warden on the same changes.

references/config-schema.mdMEDIUM
48.6%

Tool passed security scan

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
5
Files Flagged
5
Chunks Analyzed
5
Analyzed
Feb 22, 2026, 11:12 AM
Security Audit — runlayer — warden