Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill automates CLI regeneration but contains a risk where data from potentially untrusted research files is executed in a Python subprocess without proper sanitization. This could allow a malicious CLI registry entry to execute arbitrary code. It also ingests external data into prompts for other tools without strict validation.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue