Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill creates a significant security risk by dynamically discovering and executing instructions from other skills without user oversight. Its 'surprise' design explicitly discourages transparency, making it an ideal vector for indirect prompt injection or 'confused deputy' attacks where a malicious skill could be triggered and executed silently.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn1/1 file flagged