Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill consists of instructional documentation for a MedusaJS developer tutorial. It suggests the use of high-privilege system commands (sudo), package installations, and various build and migration scripts. These are standard for local development but are flagged because automated execution of such commands by an AI agent presents security risks.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
fail13/18 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed