Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill retrieves Uniswap metadata via a CLI tool and includes instructions to download and execute code from an external registry (npm) and process data from untrusted sources, which could lead to remote code execution and indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue
Runlayer
warn1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed