Skip to content

fix: document known agentskill.sh scanner false positives#11

Open
indigokarasu wants to merge 1 commit into
agentskill-sh:mainfrom
indigokarasu:r3-false-positives
Open

fix: document known agentskill.sh scanner false positives#11
indigokarasu wants to merge 1 commit into
agentskill-sh:mainfrom
indigokarasu:r3-false-positives

Conversation

@indigokarasu
Copy link
Copy Markdown

Documents 3 known false positive patterns in the agentskill.sh security scanner:

  1. Sensitive File Access — ~/.hermes/ paths flagged as 'Access to home directory dotfiles' — these are Hermes's own operational directories
  2. Data Exfiltration — api.github.com curl calls flagged — GitHub's own public API for release metadata
  3. Social Engineering — 'Auto-approved' in command descriptions flagged — operational documentation, not urgency manipulation

Each includes explanation and scanner-safe rephrasing guidance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant