Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill contains a critical security risk within its installation instructions, which direct users to download and execute a script from a suspicious domain that typosquats the project's official domain. The execution method uses Base64 decoding to obfuscate the script's content and disables SSL verification, which are common indicators of malicious activity.
Socket
passNo alerts
Snyk
failRisk: CRITICAL · 3 issues