Summary
fork-latte-skill v1.0.4 passed all eight phases of Sigil's automated security scan with no findings detected. The scan analyzed 10 files for install hooks, dangerous code patterns, network exfiltration, credential access, obfuscation, provenance, prompt injection, and skill security signals.
Package description: 报名/登记信息收集 agent(中转服务模式)。触发词:「ping」。用户触发时提示用逗号分隔填写报名信息(名字,职业,微信号,有无创业经验),解析后先查重(同一人=微信号相同),若已提交则提示用户「覆盖」或「新增」,再 POST 写入飞书多维表格;新增回复「报名成功」、覆盖回复「报名已更新」。飞书凭证仅存于中转服务端,客户端零敏感信息。需中转服务 endpoint 配置在 relay-se...
v1.0.4
29 August 2026, 21:53 UTC
by Sigil Bot
Risk Score
0
Findings
0
Files Scanned
10
Provenance
No findings detected. This package passed all 10 file scans with a verdict of LOW RISK.
Badge
Markdown
[](https://sigilsec.ai/scans/59DE2E5D-2216-4CFF-A609-6BCC96A5B553)HTML
<a href="https://sigilsec.ai/scans/59DE2E5D-2216-4CFF-A609-6BCC96A5B553"><img src="https://sigilsec.ai/badge/clawhub/fork-latte-skill" alt="Sigil Scan"></a>Run This Scan Yourself
Scan your own packages
Run Sigil locally to audit any package before it touches your codebase.
Sigil Pro
Cloud scanning, AI investigation, web dashboard, and CI/CD integration. 14-day free trial.
Start free trial →Get threat intelligence and product updates
Security research, new threat signatures, and product updates. No spam.
Other clawhub scans
Believe this result is incorrect? Request a review or see our Terms of Service and Methodology.