autonomous-github-sync

Fail

Audited by Snyk on Jun 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The script enables remote injection of arbitrary files from a Google Drive folder into a local git repository (with automatic commit and push), and contains unsafe handling of file paths and shell-invoked arguments that can be exploited to write outside the repo, modify files without review, or achieve remote code injection—effectively acting as a backdoor/supply-chain risk if the Drive source is untrusted.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 27, 2026, 02:53 PM
Issues
1
Security Audit — snyk — autonomous-github-sync