Passed all audits
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThis skill automates the setup of research environments and identifies asset requirements (like datasets and checkpoints) by parsing repository files. It uses standard tools such as conda and pip to manage dependencies. The primary security consideration is its inherent susceptibility to indirect prompt injection when processing untrusted third-party repositories, which could influence the setup plan or installation steps.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues