openharmony-download

Fail

Audited by Snyk on Feb 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The scripts are largely legitimate for downloading OpenHarmony, but they perform risky supply-chain actions (curl-downloading and executing a remote repo script, pip installing from a non-standard index, and using repo init with --no-repo-verify) that lack integrity checks and could enable malicious payload delivery.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 15, 2026, 09:42 PM