Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill resolves file system paths from user-provided input and incorporates them into shell commands. This pattern presents a risk of command injection if shell metacharacters are included in the input. Additionally, the setup script may prioritize local binaries found in the current workspace, which could lead to the execution of untrusted code if the workspace is compromised.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues