python-packaging

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • EXTERNAL_DOWNLOADS (CRITICAL): Automated scanners (URLite) identified a blacklisted URL associated with the MANIFEST.in file. This indicates a high probability of the skill attempting to fetch malicious payloads or assets from a known hostile domain.
  • REMOTE_CODE_EXECUTION (HIGH): References to blacklisted URLs in package manifest files are a common vector for injecting and executing malicious code during the installation or initialization phase of a skill.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 15, 2026, 03:58 PM