A check you can question.
Our job is to make risk legible, not to sell certainty. Here is exactly what the first engine does—and does not do.
01 / Inspect, never execute
We read SKILL.md and related text and code, checking dangerous commands, file and credential leaks, file deletion, changed security settings and misleading AI instructions. For supported code, analysis also traces where data comes from, how it is transformed and where it is sent or executed.
How AI participates
When Zhipu GLM-5.3-Flash is enabled, it independently reviews the Skill's purpose, instructions and related code, then reviews scanner findings and new AI findings against source. File paths, line numbers and quotes are checked; unsupported citations are rejected. The model cannot execute code or remove or downgrade original scanner findings. Limits, failures and unfinished reviews are disclosed.
02 / Show the work
Every finding carries a rule, file, line, short excerpt, explanation, and next step. Network access or file access alone is listed as a capability, not called malware.
03 / Admit what is missing
Static rules can miss cross-file data flows, obfuscation, changing dependencies, and runtime behavior. Binary, missing, oversized, or unreachable files reduce coverage. A clean-looking report is never a safety guarantee. Accuracy has not yet been independently benchmarked.
04 / Check a version, not a reputation
Reports record a source revision when available, a content hash, engine version, and check time. Identical inputs can reuse a report. A changed skill needs a new check.