Oathe Security Badge

Is petergyang/no-ai-slop safe?

Yes. petergyang/no-ai-slop is safe to install. Oathe's behavioral security audit gave the no-ai-slop skill by petergyang a trust score of 96/100 with 4 findings, none critical or high. Report updated

https://github.com/petergyang/no-ai-slop

96
SAFE

Is petergyang/no-ai-slop safe to install?

The no-ai-slop skill by Peter Yang is a legitimate, well-constructed writing assistance tool that edits drafts to remove AI-generated language patterns while preserving the author's voice. The SKILL.md contains no prompt injection vectors, no filesystem or network access instructions, and no credential-harvesting mechanisms. All monitoring evidence — canary file integrity, network destinations, filesystem diff, and process execution — is consistent with a benign git clone and a purely text-in/text-out skill payload.

What security issues were found in petergyang/no-ai-slop?

Category Scores

Prompt Injection 97/100 · 30%
Data Exfiltration 96/100 · 25%
Code Execution 95/100 · 20%
Clone Behavior 90/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 96/100 · 5%

Findings (4)

INFO Contextually appropriate editor persona -3 ▶

The skill assigns the LLM the role of 'a sharp human editor.' This is standard, bounded, and contextually appropriate for a writing tool. There are no instructions to ignore prior context, suppress output, act outside the editing domain, or escalate permissions.

INFO Build script is a benign packaging utility -5 ▶

scripts/build_plugin.py validates manifest fields, copies static files, and produces a ZIP archive for plugin distribution. No exec, subprocess, network, or dynamic code patterns are present.

INFO Expected GitHub and Ubuntu OS network activity only -10 ▶

The only external connections observed were to GitHub (clone source) and Ubuntu's Canonical server (triggered by SSH login MOTD scripts, entirely unrelated to the skill). No unexpected beaconing or data upload.

INFO Canary file reads are from audit harness, pre-dating skill install -4 ▶

Sensitive credential file reads occur 5 seconds before the git clone command executes, consistent with the audit harness establishing canary baselines. A second read batch after install is consistent with post-install integrity verification. The skill has no mechanism to read or transmit files.

Should I install petergyang/no-ai-slop?

Oathe's verdict for petergyang/no-ai-slop is SAFE with a trust score of 96/100. Recommendation: Install.