What the scan looks for, and what it does not prove.
Nothing has been scanned yet. New manual listings without a source get scanned on their first content change.
No indicators found by the current scan version. This is a heuristic result, not a guarantee.
Scanned and additionally reviewed by a human.
Medium-severity indicators. Usually a legitimate command mentioned in prose; read the security section before installing.
High or critical indicators found. The skill is held for review and heavily discounted in ranking.
Multiple critical indicators. Cannot be published or ranked.
The scanner reads text. It can’t execute a skill, can’t follow every link, and can’t know what a model will do with an ambiguous instruction. Treat “Scanned” as “nothing obvious”, not “safe”. Read the source before you run anything with access to your machine or accounts, and report anything that behaves differently from its description.