Self-hosted personal assistant for Claude Code — mail, calendar, Slack, scheduled briefings.
No risk signals detected.
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 1w ago · see ecosystem CVEs →
- B · 22 → A · 0
- A · 0 → B · 22
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
analyzed commit 4a2829c · analyzer v33 · 2w ago
skills & prompt files 9
- agent-rules purroy-majordomo-4a2829c/.claude/commands/auth.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/book.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/evening.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/goals.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/inbox.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/morning.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/reply.md
- agent-rules purroy-majordomo-4a2829c/.claude/commands/schedule.md
- agent-rules purroy-majordomo-4a2829c/CLAUDE.md
danger signals2
- suspicious endpoint api.telegram.org purroy-majordomo-4a2829c/scripts/telegram_api.py :37
url = f"https://api.telegram.org/bot{token}/{method}" - suspicious endpoint api.telegram.org purroy-majordomo-4a2829c/scripts/telegram_bot.py :99
url = f"https://api.telegram.org/bot{token}/{method}"
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of purroy.