adobe-express
Fail
Audited by Snyk on Feb 28, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). These URLs are suspicious because they point to direct .sh installers on an unverified third‑party domain (canifi.com), include a curl | bash install pattern and tooling that requests/stores credentials—classic high‑risk behavior for malware distribution or credential exfiltration.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's Quick Install and Setup include curl ... | bash commands that fetch and execute remote scripts (https://canifi.com/skills/adobe-express/install.sh and https://canifi.com/install.sh), which run remote code as part of installing/bootstrapping the skill and are required for it to function.
Audit Metadata