Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe domain-hunter skill is rated HIGH risk primarily because it instructs the AI agent to access and read the user's private shell configuration file (~/.zshrc) to retrieve API keys. It also processes information from public social media sites like Twitter and Reddit without proper safety filters, which could allow malicious posts to hijack the agent's behavior through indirect prompt injection.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn5/5 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed