BlueSkills false negative: macOS credential-theft PoC rated CLEAN 0/100
BlueSkills returned CLEAN — 0/100 with no findings for a skill whose code attempts SSH private-key exfiltration on its first invocation on macOS, its declared supported platform.
The exact same ZIP received two CLEAN responses. All relevant code is included as plaintext Python; there are no remote instructions, binary payloads, or delayed triggers.
The PoC uses example.com as required and was never executed locally.
The GitHub issue includes the exact ZIP, SHA-256, complete bot responses, screenshots, and reproduction details:
https://github.com/BluethroatLabs/blueskills-public/issues/2