code-push
Fail
Audited by Snyk on Jul 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). This is a direct raw GitHub URL to an install.sh script that the docs instruct to fetch and pipe to bash — executing remote shell scripts without review is a high-risk distribution vector even if hosted on GitHub.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The curl command in the setup and CI instructions fetches and pipes a remote install script that is executed at runtime (https://raw.githubusercontent.com/shorebirdtech/install/main/install.sh), so remote code is run and influences the agent environment.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata