release

Fail

Audited by Snyk on Mar 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 1.00). This is a direct raw GitHub link to an install.sh in a personal repository and the skill explicitly pipes it to bash (curl ... | bash), which is high-risk because running unreviewed remote shell scripts from an individual/unverified source can execute arbitrary malicious code.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 10, 2026, 04:51 AM