spider-king

Pass

Audited by Gen Agent Trust Hub on Jun 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, security vulnerabilities, or hardcoded credentials were found in the skill or its associated scripts.
  • [SAFE]: Deterministic detections for obfuscation and base64 execution chains in references/offline-inline-deob-playbook.md are false positives. These strings occur in descriptive documentation explaining how to recognize common patterns used by external websites to hide logic, rather than being executable payloads within the skill itself.
  • [SAFE]: The skill uses chrome-devtools-mcp and js-reverse-mcp strictly for reconnaissance and evidence gathering as part of its methodology, emphasizing that final collectors should be browser-free Python scripts.
  • [SAFE]: The provided Python scripts (check_reverse_env.py, crypto_fingerprint.py, protocol_diff.py, scaffold_reverse_project.py) are legitimate utility tools for environment verification, data fingerprinting, and boilerplate generation that do not exhibit suspicious behaviors or path traversal risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 10, 2026, 10:04 AM
Security Audit — agent-trust-hub — spider-king