Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill is generally functional but contains a significant security risk regarding how it handles user input. It recommends executing shell commands using URLs provided by users, which can lead to command injection. Additionally, it processes untrusted website content to generate instructions for other AI agents, creating a surface for indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 2 issues