clipboard-sync-cross-device
Fail
Audited by Snyk on Jul 1, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The GitHub repo is from an individual/unknown user (potentially low-audit) and combined with the OAuth Drive scope (https://www.googleapis.com/auth/drive.file) and the nature of a clipboard-sync tool (can access and exfiltrate sensitive clipboard data) makes this a potentially high-risk source for sensitive-data leakage or abuse, even though ara.so and GitHub are not inherently malicious hosting platforms.
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata