commit-message

Fail

Audited by Snyk on Mar 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The proxy URL appears to be a benign corporate proxy, but the raw.githubusercontent.com link is a direct raw shell script (curl | bash style) — executing remote .sh from a repository (even a known user) is inherently risky and should be inspected before running.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 7, 2026, 09:23 PM