Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill instructs the agent to install a plugin from an unverified third-party GitHub repository and subsequently executes Python scripts from that plugin. This pattern represents a high-risk remote code execution vector. Additionally, the skill processes external repositories without sanitization, creating a surface for indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn5/5 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed