quark-netdisk

Fail

Audited by Snyk on Mar 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These URLs include an instruction to pip-install a GitHub repo owned by an unfamiliar/random-named account (z1w2r3) and reference other small GitHub forks — installing directly from such unvetted repos can run arbitrary code at install/runtime and is therefore suspicious even if a PyPI page exists.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 7, 2026, 04:49 AM