Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill contains instructions that attempt to bypass user confirmation for shell command execution. It also relies on unversioned remote code execution via npx and performs dynamic generation of HTML/CSS content which is rendered by a headless browser.
Socket
warn1 alert: gptSecurity
Snyk
passRisk: LOW · No issues