Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill downloads content from a user-provided URL, injects it into a source code file (.tsx), and executes a render command. This pattern allows an attacker to perform code injection and achieve remote code execution (RCE) by providing a malicious URL that breaks out of the source code string literal.
Socket
warn1 alert: gptAnomaly
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed