Is cengicadis/blankvisuals-validator safe?
Yes. cengicadis/blankvisuals-validator is safe to install. Oathe's behavioral security audit gave the blankvisuals-validator skill by cengicadis a trust score of 90/100 with 6 findings, none critical or high.
https://github.com/cengicadis/blankvisuals-validator
Is cengicadis/blankvisuals-validator safe to install?
BlankVisuals Validator (FW-001 v1.0.3) is a read-only meta-validation framework for AI agent skills that presents no evidence of malicious intent: the SKILL.md contains no prompt injection, override instructions, or data exfiltration channels, and monitoring confirmed no unexpected network connections, canary file compromise, or executable code execution during installation. The primary residual concerns are low-severity: the skill's authority-framing as an official validator could be socially misused by future forks, and its by-design behavior of reading target SKILL.md files exposes the agent to content from arbitrary third-party repositories during validation runs. The repository is incomplete relative to its own documentation (missing verify.sh, USAGE.md, CHANGELOG.md), which is a quality issue rather than a security one.
What security issues were found in cengicadis/blankvisuals-validator?
Category Scores
Findings (6)
LOW Meta-validator authority framing -8 ▶
The skill positions itself as an authoritative validation framework (FW-001) and produces structured PASS/FAIL verdicts on other skills. While the skill itself is benign, this authority framing could be exploited in future versions or forks to issue fraudulent 'PASS' certifications that users trust when installing other skills.
LOW Target SKILL.md content read into agent context -12 ▶
As a meta-validator, this skill instructs the agent to read and process the SKILL.md of arbitrary target repositories. If a target SKILL.md contains secrets, credentials embedded as examples, or injected instructions, those would enter the agent's context during a validation run. This is disclosed behavior but represents a data surface the user should be aware of.
LOW Referenced scripts absent from repo -4 ▶
README.md and docs/PR-CHECKLIST.md reference scripts/verify.sh, docs/USAGE.md, and CHANGELOG.md as required files, but none are present in the cloned repository. This is documentation drift rather than a security issue, but indicates the published repo is incomplete relative to its own spec.
INFO Clean installation with expected GitHub-only network activity 0 ▶
The git clone connected only to GitHub (140.82.121.3:443) as expected. No post-install beacon, DNS exfiltration, or unexpected process was observed. The connection to 185.125.188.58:443 was pre-existing Ubuntu infrastructure, not skill-related.
INFO Canary file accesses attributed to audit monitoring system 0 ▶
Filesystem and auditd logs show accesses to .env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and gcloud credentials. All such accesses occur at timestamps before the git clone (1788926558 vs clone at 1788926564) and at the audit teardown phase (1788926580), consistent with the monitoring pipeline's own baseline and integrity-check reads. The skill itself initiated none of these accesses.
INFO Injection-prevention design is present and documented 0 ▶
The skill explicitly states that user-provided rules in VALIDATION.md are ignored to prevent injection, and documents this design decision in CONTRIBUTING.md and SKILL.md. This is a positive security signal indicating the author was aware of and mitigated a known attack vector for meta-validator skills.
Should I install cengicadis/blankvisuals-validator?
Oathe's verdict for cengicadis/blankvisuals-validator is SAFE with a trust score of 90/100. Recommendation: Install.