help
Fail
Audited by Snyk on Feb 20, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Two URLs are official Pinecone pages (docs and signup) and are low risk, but the astral.sh link is a direct install.sh intended to be curl | sh from a third‑party domain — a high‑risk distribution method that can deliver arbitrary code and should be treated as suspicious.
Audit Metadata