Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill contains a critical security risk by instructing users to execute a remote shell script using 'curl | bash' from an untrusted third-party repository. Additionally, the autonomous agent loop architectures described in the skill are vulnerable to indirect prompt injection as they ingest untrusted data like external specifications and CI logs without adequate sanitization or boundary markers.
Socket
warn1 alert: gptSecurity
Snyk
failRisk: CRITICAL · 3 issues
Runlayer
warn1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed