autonomous-loops

Fail

Audited by Snyk on Mar 6, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). This is a direct raw GitHub URL to an install.sh shell script that the skill suggests piping to bash (curl | bash); hosting on raw.githubusercontent.com and a known username reduces but does not eliminate risk — executing a remote .sh without inspecting it is inherently dangerous and can distribute malware.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 6, 2026, 02:12 AM