ToolProof Trust Profile

ai-example4-xmp4

Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.

43risk score
Review Firstconnection signal
destructive_capabilityrisk type
29evidence score
Source: https://github.com/0ics-srls/lsai-xmp4.public
Registry: ai.example4/xmp4 1.2.6

Connection signal

Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.

Observed tools

  • None observed in this static profile.

Top findings

  • Install risk pattern: curl_pipe_shell — html/llms.txt:12
  • Detected capability: filesystem_write_delete — scripts/sync-skill.sh:21

Recommended controls

  • Install in a sandbox before team or production use.
  • Pin the exact package/repository version.
  • Review install scripts, Dockerfile behavior, and dependency pins.
  • Do not use production credentials during first install.
  • Restrict filesystem, repository, cloud, and database scope.
  • Require human approval for destructive actions.