ghost-validate

Warn

Audited by Runlayer on Feb 23, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
2
Flagged
2
Chunks
2
Flagged Files (2)
SKILL.mdHIGH
78.3%

Malicious tool definition detected

Tool: SKILL.md Description: --- name: "ghost-validate" description: This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerability findings by tracing data flows, verifying exploit conditions, analyzing security controls, and optionally testing attack vectors

VULNERABILITY_PATTERNS.mdHIGH
78.3%

Malicious tool definition detected

Tool: VULNERABILITY_PATTERNS.md Description: # Vulnerability Class Reference ## Authorization Flaws (BFLA/BOLA/IDOR) Look for: - Missing ownership checks in database queries (e.g., no `UserId` in WHERE clause) - Inconsistent authorization between similar operations (e.g., destination checked but source not checked) - Direct object references without access control - Horizontal privilege escalation (accessing other users' resources) - Vertical privilege escalation (accessing admin functions)

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
2
Files Flagged
2
Chunks Analyzed
2
Analyzed
Feb 23, 2026, 11:06 PM
Security Audit — runlayer — ghost-validate