find-skills

Fail

Audited by Snyk on Sep 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (critical risk: 1.00). The script downloads and executes code and archives from external domains (lightmake.site and Tencent COS) that are not part of any official software distribution, presenting a critical risk of untrusted arbitrary code execution.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The agent searches and fetches skill metadata and archives from public SkillHub endpoints (skillhub.tencent.com and lightmake.site), which represents outsider-searchable public registry content accessed actively by user request.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill downloads and executes runtime components from arbitrary third-party infrastructure (lightmake.site and tencentcloud.com), constituting an unverifiable external runtime dependency with weak or unknown publisher provenance.

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 01:58 AM
Issues
3
Security Audit — snyk — find-skills