Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill is vulnerable to ZipSlip (path traversal) which allows arbitrary file writes during the unpacking of Office documents. It also contains XML External Entity (XXE) vulnerabilities in document validation scripts.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn55/55 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed