Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThis skill downloads, builds, and executes source code from an external GitHub repository. While this is the intended functionality for importing CLI tools, it introduces risks from running untrusted code. It also lacks sanitization for data fetched from the remote registry, creating a surface for indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue