skill-installer

Fail

Audited by Snyk on Jul 12, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The set includes a high-risk MCP connector URL (https://mcp.example.com/server) that can enable remote execution/credentialed access and is not an innocuous documentation or official vendor download, while the other links point to government sites or an allowed GitHub registry and are not suspicious in this context.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Yes—Step 3 (“展示原始 SKILL.md”) and Step 5 (“运行 skills-qa”) require the agent to ingest and process the candidate skill’s outsider-authored free text (the third-party SKILL.md and related files) into the LLM context at runtime.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 12, 2026, 01:02 AM
Issues
2
Security Audit — snyk — skill-installer