Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill provides a development toolkit for Claude Code hooks. It contains a high-severity shell injection vulnerability in the testing utility script and provides example security hooks that are highly vulnerable to bypass (Indirect Prompt Injection) while handling sensitive permission decisions.
Socket
warn1 alert: gptSecurity
Snyk
passRisk: LOW · No issues
Runlayer
warn11/11 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed