skill-installer
Fail
Audited by Snyk on Jul 12, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The set includes a high-risk MCP connector URL (https://mcp.example.com/server) that can enable remote execution/credentialed access and is not an innocuous documentation or official vendor download, while the other links point to government sites or an allowed GitHub registry and are not suspicious in this context.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes—Step 3 (“展示原始 SKILL.md”) and Step 5 (“运行 skills-qa”) require the agent to ingest and process the candidate skill’s outsider-authored free text (the third-party SKILL.md and related files) into the LLM context at runtime.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata