Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill uses external CLI tools (Gemini and Codex) in a highly insecure manner by explicitly bypassing user approval prompts ('yolo' and 'full-auto' modes). It also transmits local project plans to external APIs without sanitization, creating a significant risk of command execution or data exposure if the input files are compromised.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn7/7 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed