bisimulation-game
Audited by Socket on Feb 16, 2026
1 alert found:
Anomaly[Skill Scanner] Loading external skill detected All findings: [HIGH] transitive_trust: Loading external skill detected (AU004) [AITech 1.2] [HIGH] transitive_trust: Loading external skill detected (AU004) [AITech 1.2] The artifact is a benign, theory-driven specification bundle that outlines a bisimulation-based framework for resilient skill dispersion with GF(3) conservation and observational bridges. There is no evidence of malware, credential harvesting, or exfiltration within the provided fragments. As a documentation/spec artifact, its risk is low, but any downstream tooling derived from this material should enforce strict provenance, input validation, and sandboxing to prevent real-world misuse of the illustrated patterns (e.g., networked dispersion, dynamic code loading). LLM verification: The provided SKILL.md and code snippets are primarily theoretical and the shown code is benign in isolation (in-memory state, RNG, simple operations). However, the document asserts high-risk capabilities (self-rewriting via MCP Tasks, loading external skills, and mirroring to user skill directories) without safe, auditable implementations. Because of these unimplemented but dangerous claims and the scanner flags for load_skill, treat the skill as SUSPICIOUS for supply-chain risk: it could become