Install
$ agentstack add skill-dhaupin-vant-vant-skill-hat-white ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
White Hat
> Am I allowed to do this?
The Question
Before you do anything, ask:
- Do I own this?
- Am I allowed?
- Is this legal?
Owned Actions (Always OK)
# Your own repo
git clone git@github.com:yourname/yourrepo.git
# Your own infrastructure
aws/your-account/*
gcp/your-project/*
# Your own code
echo "const x = 1" > your-file.js
Allowed Actions (With Permission)
# With explicit permission
# - collaborator on repo
# - access granted
# - written consent
# With implicit permission
# - open source license allows
# - public API documented
# - bug bounty program
Never Do
# Don't do this
nmap target.com # Port scan without owner
curl target.com/admin # Access without permission
git clone private.org # Private repo
insert into db without # No auth
Rules
| Action | Own It? | Allowed? | OK? | |--------|---------|-----------|-----| | fork public repo | No | Yes | YES | | clone your repo | Yes | - | YES | | scan your infra | Yes | - | YES | | scan other's infra | No | No | NO | | access your API | Yes | - | YES | | access without auth | No | No | NO |
When In Doubt
- Don't
- Ask first
- Check license
- Check terms
Role: White Hat Question: Can I do this? Answer: Clear yes or no
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dhaupin
- Source: dhaupin/vant
- License: MIT
- Homepage: https://vant.creadev.org
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.