What the reviewer found
A secure-coding reference (catpilot-security-core) whose flagged lines are all marked negative examples (cat ~/.ssh/id_rsa | curl ..., the SSRF metadata fetch, sudo bash pipe, unpinned Dockerfile installs) shown to teach what to avoid, with remediation for each. Body was truncated at 48KB so risk is kept at low rather than none per policy.
dual-use— a security tool that can be misusedexample-or-fixture— an example or test fixture
What was read
The file as it ships in catpilotai/catpilot-ai-guardrails:
skills/catpilot-security-core/SKILL.md
What the static scan said
The scan flagged 9things. The reviewer kept 0 and dismissed 9 as false.
E1Sends data to an external URL — false positiveE2Harvests environment variables — false positivePE2Asks for root — false positivePE3Reaches for credential files — false positiveSC2Downloads and executes remote code — false positiveSSRF1Cloud metadata endpoint — false positiveRMRecursive force delete — false positiveNETMakes network calls — false positiveSHRuns shell commands — false positive
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.