Auto-derives codebase conventions from repo analysis and injects archetype-aware guidance into AI-generated code, enforcing team idioms, banned imports, and framework-specific patterns for TypeScript/JavaScript, Ruby, and Python projects.
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 12
- trust mitigators mixed − 3
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 3m ago · see ecosystem CVEs →
- C · 57 → D · 64
- C · 49 → C · 57
- A · 0 → C · 49
No known CVEs for this server.
- high dangerous code
committed secret: Slack token, AWS access key id, GitHub token · dynamic exec: __import__(), eval()/exec(), __import__ sink
analyzed commit 684e23d · analyzer v28 · 2d ago
skills & prompt files 17
- skill crisnahine-chameleon-684e23d/.claude/skills/gap-taxonomy/SKILL.md
- agent-rules crisnahine-chameleon-684e23d/CLAUDE.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-auto-idiom/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-deep-work/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-disable/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-doctor/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-explain/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-init/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-journey/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-pause-15m/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-pr-review/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-receiving-code-review/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-refresh/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-status/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-teach/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/chameleon-trust/SKILL.md
- skill crisnahine-chameleon-684e23d/plugin/skills/using-chameleon/SKILL.md
danger signals7
- dynamic code execution __import__() crisnahine-chameleon-684e23d/plugin/mcp/chameleon_mcp/extractors/treesitter/grammars.py :79
module = __import__(module_name, fromlist=[factory_attr]) - dynamic code execution eval()/exec() crisnahine-chameleon-684e23d/plugin/mcp/chameleon_mcp/lint_engine.py :466
Used by the sink/style/convention scans so an ``eval(`` mentioned in a - dynamic code execution __import__() crisnahine-chameleon-684e23d/tests/unit/test_bootstrap_orchestrator.py :988
lambda self, repo_root, glob="**/*", limit=None, paths=None: __import__( - dynamic code execution __import__ sink crisnahine-chameleon-684e23d/tests/unit/test_review_fix3_tools_autopass.py :446
real_replace = __import__("os").replace - committed secret Slack token crisnahine-chameleon-684e23d/tests/unit/test_intent_capture.py :398
xoxb-2…(28 chars, redacted) - committed secret AWS access key id crisnahine-chameleon-684e23d/tests/unit/test_qa26_remediation.py :23
AKIAQA…(20 chars, redacted) - committed secret GitHub token crisnahine-chameleon-684e23d/tests/unit/test_secret_coverage.py :290
ghp_16…(40 chars, redacted)
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of crisnahine.