seo-content-brief

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The presence of an unknown domain serving a curl | sh installer (https://cli.inference.sh) — which downloads and executes a remote shell script directly — is a high-risk distribution pattern (while the top-result-*.com pages look like generic placeholders and are lower risk), so overall this set is suspicious for malware distribution.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly instructs the agent to fetch and analyze open web content (e.g., "infsh app run tavily/extract --input {'urls': [...]}," SERP analysis and search commands) which ingests arbitrary public URLs/top-ranking pages and expects the agent to read and interpret that untrusted third‑party content.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 02:57 AM