sruja-architecture

Fail

Audited by Snyk on Mar 18, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Visual Studio Marketplace and GitHub are reputable hosts, but the package’s own domain exposing a direct install.sh (intended to be curl|bash’d) is a high‑risk distribution pattern — remote shell installers from an unverified project/domain can easily deliver malware.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 18, 2026, 04:21 AM
Issues
1