Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThis skill extracts brand identity from website URLs. It is vulnerable to command injection because it executes a local Python script using a user-provided URL as a command-line argument without explicit sanitization. Furthermore, the skill processes untrusted content from external websites, creating a surface for indirect prompt injection that could influence the generated brand profile.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 2 issues
Runlayer
pass1/1 file flagged
ZeroLeaks
pass1 finding · Score: 86/100