skill-installer

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's scripts (scripts/list-skills.py and scripts/install-skill-from-github.py) explicitly fetch content from GitHub (via the GitHub API and codeload/git clone of arbitrary owner/repo or user-provided URLs) and install those public or user-supplied repo files into $CODEX_HOME/skills, meaning untrusted third-party content is ingested and can materially alter the agent's behavior by adding new skills.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 06:33 AM