mobile-use-setup

Fail

Audited by Snyk on Feb 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). astral.sh/uv/install.sh is high-risk because it is a direct shell script served from a third‑party domain and the skill instructs piping it to sh (allowing arbitrary remote code execution), whereas platform.minitap.ai appears to be an official service domain and is not a direct executable download.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 15, 2026, 10:16 PM