Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill performs web searches and extracts content using the Brave Search API. Its primary security risk is Indirect Prompt Injection, as it retrieves and processes untrusted web content that could contain malicious instructions for the AI agent. Additionally, the lack of URL validation allows for potential Server-Side Request Forgery (SSRF) against internal network resources.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn6/6 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed