Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill facilitates entity discovery using the parallel-cli tool. It contains a security risk where user-provided input is directly interpolated into shell commands. This could allow a malicious user to perform command injection and execute unauthorized code on the host system. Additionally, the skill lacks safeguards against indirect prompt injection in the search parameters.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 1 issue