← back to validating-tpm-measured-boot-attestation
SkillMD Review · validating-tpm-measured-boot-attestation
our safety review · skill by mukul975
Runs sudo commands to read TPM, create keys, and seal/unseal data; uses tpm2-tools for legitimate attestation workflows.
reviewed 2026-07-16
What the verdicts mean
No risky instructions — documentation or standard, read-only development-tool usage.
Legitimate purpose with real capabilities (runs scripts, calls services, or handles credentials). Read the skill before installing.
Risky patterns beyond the skill's job — elevated privileges, config changes, or bypassed confirmations. Review carefully.
Instructions a safe skill should never contain — injection, exfiltration, or destructive commands. Don't install unless you've verified the source.
Could not be confidently assessed — treat as unreviewed and inspect the SKILL.md yourself.