Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill implements a 'Generate-then-Execute' pipeline that creates and runs arbitrary Python code on the local system based on user-provided descriptions. This pattern is highly susceptible to prompt injection attacks where a malicious request could cause the agent to generate and execute code that deletes files, exfiltrates sensitive data, or installs malware.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
pass3/3 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed