Humanizer: why it is not safe to use
Humanizer passed our review: we found a local, readable text-rewriting skill with no hidden instructions, credential access, or undeclared outbound data flow.
What we found
Humanizer passed our security and privacy review with a score of 93/100. In the scanned repository, we found a local Markdown-based skill that clearly states when to use it and keeps its behavior in visible prompt files. We did not find hidden or disguised instructions, encoded payloads, or minified content.
We also did not find signs of undeclared outbound data transfer. The repository does not declare a destination for sending user text, and we found no runtime fetching or execution of remote code from undisclosed sources. No hardcoded credentials, tokens, or API keys were present in the inspected files.
The skill appears limited to rewriting pasted text or prose in a user-specified file. We did not find behaviors that access environment variables, browser data, SSH keys, keychains, or other credentials beyond the text or file a user provides. We also did not find delete, overwrite-all, publish, sudo, permission-changing, or sandbox escape paths.
What to do instead
This skill can be used as reviewed for local text rewriting. As with any writing assistant, avoid pasting sensitive material unless your workflow permits it, and keep the skill pinned to the reviewed repository version if you need the same review posture.
Source: https://github.com/blader/humanizer
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.