Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill contains a critical security risk. The installation instructions include a command that downloads and executes obfuscated code from a suspicious domain designed to look like the official project domain. This allows for arbitrary remote code execution on the user's system.
Socket
warn1 alert: gptSecurity
Snyk
failRisk: CRITICAL · 5 issues