Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis markdown-based skill is highly vulnerable to indirect prompt injection. It directs an agent to analyze untrusted git commit history and perform file system writes without providing security boundaries or sanitization instructions, which could allow malicious commit messages to hijack the agent's behavior.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
pass1 file scanned · No issues
ZeroLeaks
passScore: 93/100 · 2 sections analyzed