Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThe skill provides instructions for bypassing Linux security controls and includes a confirmed remote code execution pattern using a piped curl command from an untrusted domain. It also details methods for reading sensitive files like /etc/shadow and includes instructions to override AI safety constraints.
Socket
fail1 alert: gptMalware
Snyk
failRisk: CRITICAL · 4 issues
ZeroLeaks
pass1 finding · Score: 82/100