Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill provides a coding agent persona with hooks for task logging and project linting. It contains a shell command injection vulnerability in the pre-hook where the task description is echoed without sanitization, and it runs potentially untrusted scripts via npm in the post-hook.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
pass1 file scanned · No issues
ZeroLeaks
passScore: 93/100 · 2 sections analyzed