Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill allows for Remote Code Execution (RCE) by instructing the agent to clone an untrusted repository and execute its installation and startup scripts. It also lacks security boundaries when reading external documentation, creating an indirect prompt injection risk.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
warn1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed