Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill contains an insecure 'Stop' hook that dynamically searches for and executes scripts within a cache directory, which could lead to arbitrary command execution. It also includes a context recovery script that re-injects content from previous session logs into the current prompt without sanitization, creating a significant surface for indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue
ZeroLeaks
passScore: 93/100 · 2 sections analyzed