antigravity-lazy-packs
Fail
Audited by Snyk on Jun 9, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The links point to a mix of a known site (cc.lifehacker.tw) and a set of GitHub repos from an individual/unknown account (mathruffian-dot) plus an external vendor (firecrawl.dev); while there are no direct .exe downloads, the skill docs instruct using npx/npm/pip (commands that can execute arbitrary third‑party code) and the GitHub account is not a well‑known/verified vendor, so this represents a moderate supply‑chain risk and should be treated with caution.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The GitHub repo https://github.com/mathruffian-dot/antigravity-lazy-pack is explicitly fetched at runtime via commands like "npx skills add mathruffian-dot/antigravity-lazy-pack" (and the README tells the agent to read that repo), which installs remote skill files (SKILL.md) that directly define/modify agent prompts/behavior and may run remote code, so it is a runtime external dependency that controls the agent.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). It directs the agent to run global npm/npx installs (npx ... -g -y) and to "execute" instructions from SKILL.md (arbitrary commands), which modifies the host system and may require elevated privileges or run unsafe code, so it poses a high risk of compromising machine state.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (4)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata