seo-content-brief
Fail
Audited by Snyk on Feb 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The presence of an unknown domain serving a curl | sh installer (https://cli.inference.sh) — which downloads and executes a remote shell script directly — is a high-risk distribution pattern (while the top-result-*.com pages look like generic placeholders and are lower risk), so overall this set is suspicious for malware distribution.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly instructs the agent to fetch and analyze open web content (e.g., "infsh app run tavily/extract --input {'urls': [...]}," SERP analysis and search commands) which ingests arbitrary public URLs/top-ranking pages and expects the agent to read and interpret that untrusted third‑party content.
Audit Metadata