Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThis skill facilitates reading Twitter/X content for financial research by utilizing the third-party 'opencli' tool. It presents an indirect prompt injection risk by ingesting untrusted data from social media and uses dynamic context injection to check tool status at load time. Users are required to install external dependencies, including a Node.js package and a Chrome extension from a non-vendor source.
Socket
warn1 alert: gptAnomaly
Snyk
warnRisk: MEDIUM · 1 issue
ZeroLeaks
passScore: 93/100 · 2 sections analyzed