Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe configuration defines several Model Context Protocol (MCP) servers that execute local and remote code. The primary security concerns are the use of 'npx -y' to dynamically download and execute npm packages and the granting of local filesystem access to the agent.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
fail3/7 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed