clipboard-sync-cross-device

Fail

Audited by Snyk on Jul 1, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The GitHub repo is from an individual/unknown user (potentially low-audit) and combined with the OAuth Drive scope (https://www.googleapis.com/auth/drive.file) and the nature of a clipboard-sync tool (can access and exfiltrate sensitive clipboard data) makes this a potentially high-risk source for sensitive-data leakage or abuse, even though ara.so and GitHub are not inherently malicious hosting platforms.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 1, 2026, 09:05 PM
Issues
1
Security Audit — snyk — clipboard-sync-cross-device