Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill is designed to scrape and analyze web novel platforms but contains a significant Command Injection vulnerability in its core utility script. It also programmatically harvests session authentication tokens from browser cookies and is susceptible to indirect prompt injection from the untrusted web content it retrieves.
Socket
warn2 alerts: gptAnomaly
Snyk
failRisk: HIGH · 3 issues