Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill installs and executes external software from an individual's GitHub repository. It uses scripts to clone, compile, and link a community-maintained Salesforce CLI plugin and suggests running a remote Python script directly from the internet via pipe-to-shell. These patterns represent significant remote code execution and supply chain risks.
Socket
warn2 alerts: gptSecurity
Snyk
failRisk: CRITICAL · 2 issues