swarm-platform@ 3.0.0

github.com/clawhub.ai/swarm-platform
Verdict: Proceed with caution
0 critical0 high6 medium
C
SCORE 55 / 100
$skillox install swarm-platformSoon
Sign in to followFollowing emails you when a re-scan drops the grade. Opt-out is per-creator on /account/billing.

Why grade C?

score · 55 / 100

The current grade reflects 6 medium findings (6+ MEDs → C).

0 CRIT0 HIGH6 MED0 LOW
To reach a higher grade
  • B
    Reach Btarget score 75

    Resolve 1 of 6 MED (cap is 5).

  • A
    Reach Atarget score 95

    Resolve 4 of 6 MED (cap is 2).

Thresholds are documented at /docs/grading. Source-of-truth is the grade() function in @skillox/scanner.

Latest scan findings

Scan crawl-i9f43fvzc82pucq71mmg1rm7 · Thu, 28 May 2026 16:39:06 GMT · 4ms

med
No capability manifest declared
The skill ships without a `manifest.yaml` or `capabilities` block in its frontmatter. Without a manifest, the runtime cannot enforce what this skill is permitted to do.
rule: no-manifest
med
Link text shows "authentication.md" but points at swarmprotocol.org
The visible link text contains the domain `authentication.md`, but the URL actually targets `swarmprotocol.org`. This is a phishing/smuggling pattern — the reader sees one host, the agent fetches another. Either update the text or the URL so they match.
rule: anchor-href-mismatchline: 450CWE-601
448| Document | Purpose |
449|----------|---------|
450| [authentication.md](https://swarmprotocol.org/docs/authentication.md) | Complete auth deep dive |text→authentication.md · href→swarmprotocol.org
451| [api-endpoints.md](https://swarmprotocol.org/docs/api-endpoints.md) | All endpoints with schemas |
452| [verification-guide.md](https://swarmprotocol.org/docs/verification-guide.md) | Advanced verification |
med
Link text shows "api-endpoints.md" but points at swarmprotocol.org
The visible link text contains the domain `api-endpoints.md`, but the URL actually targets `swarmprotocol.org`. This is a phishing/smuggling pattern — the reader sees one host, the agent fetches another. Either update the text or the URL so they match.
rule: anchor-href-mismatchline: 451CWE-601
449|----------|---------|
450| [authentication.md](https://swarmprotocol.org/docs/authentication.md) | Complete auth deep dive |
451| [api-endpoints.md](https://swarmprotocol.org/docs/api-endpoints.md) | All endpoints with schemas |text→api-endpoints.md · href→swarmprotocol.org
452| [verification-guide.md](https://swarmprotocol.org/docs/verification-guide.md) | Advanced verification |
453| [proposals-voting.md](https://swarmprotocol.org/docs/proposals-voting.md) | Governance details |
med
Link text shows "verification-guide.md" but points at swarmprotocol.org
The visible link text contains the domain `verification-guide.md`, but the URL actually targets `swarmprotocol.org`. This is a phishing/smuggling pattern — the reader sees one host, the agent fetches another. Either update the text or the URL so they match.
rule: anchor-href-mismatchline: 452CWE-601
450| [authentication.md](https://swarmprotocol.org/docs/authentication.md) | Complete auth deep dive |
451| [api-endpoints.md](https://swarmprotocol.org/docs/api-endpoints.md) | All endpoints with schemas |
452| [verification-guide.md](https://swarmprotocol.org/docs/verification-guide.md) | Advanced verification |text→verification-guide.md · href→swarmprotocol.org
453| [proposals-voting.md](https://swarmprotocol.org/docs/proposals-voting.md) | Governance details |
454| [sync-optimization.md](https://swarmprotocol.org/docs/sync-optimization.md) | Advanced caching |
med
Link text shows "proposals-voting.md" but points at swarmprotocol.org
The visible link text contains the domain `proposals-voting.md`, but the URL actually targets `swarmprotocol.org`. This is a phishing/smuggling pattern — the reader sees one host, the agent fetches another. Either update the text or the URL so they match.
rule: anchor-href-mismatchline: 453CWE-601
451| [api-endpoints.md](https://swarmprotocol.org/docs/api-endpoints.md) | All endpoints with schemas |
452| [verification-guide.md](https://swarmprotocol.org/docs/verification-guide.md) | Advanced verification |
453| [proposals-voting.md](https://swarmprotocol.org/docs/proposals-voting.md) | Governance details |text→proposals-voting.md · href→swarmprotocol.org
454| [sync-optimization.md](https://swarmprotocol.org/docs/sync-optimization.md) | Advanced caching |
455
med
Link text shows "sync-optimization.md" but points at swarmprotocol.org
The visible link text contains the domain `sync-optimization.md`, but the URL actually targets `swarmprotocol.org`. This is a phishing/smuggling pattern — the reader sees one host, the agent fetches another. Either update the text or the URL so they match.
rule: anchor-href-mismatchline: 454CWE-601
452| [verification-guide.md](https://swarmprotocol.org/docs/verification-guide.md) | Advanced verification |
453| [proposals-voting.md](https://swarmprotocol.org/docs/proposals-voting.md) | Governance details |
454| [sync-optimization.md](https://swarmprotocol.org/docs/sync-optimization.md) | Advanced caching |text→sync-optimization.md · href→swarmprotocol.org
455
456---
View latest scan →
skillox.io/c/swarm-platform