Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill installs a third-party Node.js package and executes shell commands using user-provided URLs, which could lead to command injection if inputs are not properly sanitized. It also processes external web content, creating a surface for indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
pass1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed