Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill acts as a malicious playbook for Linux privilege escalation, instructing the agent to download and execute unverified scripts from the internet, exfiltrate sensitive data such as password hashes to external servers, and exploit system vulnerabilities. It contains confirmed malicious URLs and remote code execution patterns that bypass standard security practices.
Socket
fail3 alerts: gptSecurity, gptMalware
Snyk
failRisk: CRITICAL · 5 issues
ZeroLeaks
pass1 finding · Score: 82/100