Every single one of the 18 skills provided by the Skill Hub on @binance Agent OS is now included in SafuSkill. According to public automated scan logs documented as of Aug 21, 2026, the entire collection of 18 skills achieved an aggregate risk classification of LOW. Furthermore, translating the public riskScore metrics results in an excellent mean score of 97.4/100.
Any additional flagged signals are entirely consistent with their original source contexts. Specifically, the p2p module triggered a high-severity upload pattern solely because it transmits appeal evidence to a presigned URL. Regarding the binance-wallet-tracker, the scan highlighted three low-severity Unicode-confusable heuristics, though these findings offer no evidence of malicious intent. Finally, the fiat skill produced one informational finding that recommends refining the allowed-tools declaration to better handle external network access.
Please keep in mind that while these public reports highlight a current lack of exploitable vulnerabilities, they cannot guarantee permanent safety. The reviewed code only reflects a specific point in time, the logs cover multiple different scan dates, and there are no pinned commit SHAs made available.
For your own security, always take a moment to confirm the specific version, check the allowed permissions, and review the outbound destinations before you run your agent.
Go Agentic. Stay Safu!
Any additional flagged signals are entirely consistent with their original source contexts. Specifically, the p2p module triggered a high-severity upload pattern solely because it transmits appeal evidence to a presigned URL. Regarding the binance-wallet-tracker, the scan highlighted three low-severity Unicode-confusable heuristics, though these findings offer no evidence of malicious intent. Finally, the fiat skill produced one informational finding that recommends refining the allowed-tools declaration to better handle external network access.
Please keep in mind that while these public reports highlight a current lack of exploitable vulnerabilities, they cannot guarantee permanent safety. The reviewed code only reflects a specific point in time, the logs cover multiple different scan dates, and there are no pinned commit SHAs made available.
For your own security, always take a moment to confirm the specific version, check the allowed permissions, and review the outbound destinations before you run your agent.
Go Agentic. Stay Safu!