how-to-download-skool-videos

Fail

Audited by Snyk on Apr 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These links point to GitHub repos/releases, raw GitHub/gist content, and a short URL from small/unknown authors that are used to distribute a browser extension and command-line instructions—there are no direct .exe installers shown but installing an unvetted browser extension or running provided scripts/commands from these sources carries a moderate-to-high risk of malware or malicious behavior.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The SKILL.md explicitly says the extension "reads page data directly" and instructs the agent/user to open Skool classroom/community pages and embedded third‑party video pages (YouTube, Vimeo, Loom, Wistia), meaning it ingests untrusted, user‑generated web content and uses that content to detect and decide what to download, so third‑party page content can materially influence its actions.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 7, 2026, 04:12 PM
Issues
2