Agent Skill Security Evidence
Automated static inspection of fixed package releases. Reports describe rule matches and coverage; they do not certify that a package is safe, malicious, or compatible.
Automatic hold advisories
Only Critical rules can trigger this precautionary state. Every hold requires human review.
No current fixed release is under automatic hold. Complete current-release coverage and a no-finding result still do not mean a package is safe.
Open static signals
These are review leads, not verdicts. Open the fixed-release page for files, evidence snippets, permissions, dependencies, and coverage.
Interpretation boundary
- “No findings detected” only means the configured rules found no match in scanned text.
- Partial coverage means file-count, size, opaque-file, or read constraints limited inspection.
- Permissions and dependencies are automatically inferred indicators and may be incomplete.
- Compatibility testing and behavior sandboxing are separate evidence types and are not part of this Phase 2 static result.