pmcp

What packages did in the sandbox

Writing a skill means installing a package nobody here has read and running code against it, in a container with no route out. That produces security observations as a by-product. They are worth more than the skill, so they are published here.

Every package examined is listed, including the ones that never became a skill. A list of only what we sell would be an advertisement, and the package that got itself refused is the one worth reading about.

What this is not

Each entry records what happened in one sandboxed run under the policy named beside it. It is not a judgement of the package, and the absence of an observation is not a finding of safety. Observations at the 'manifest' and 'install' stages are the package's own behaviour; an observation at an 'example-N' stage happened while running example code we wrote against the package, and may have been caused by that code rather than by the package.

Nothing here is inferred, scored, or taken from someone else's advisory feed. Each line is something that happened in a run we executed, quoted from that run's own output.

Nothing has been examined yet.