push-notifications
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md raises a transparency concern due to an obfuscated or encoded execution path, which weakens the ability to fully review what the skill does before loading—this is the primary driver of the WARNING verdict. Prompt injection boundaries stay reasonably clear, and the skill does not push the agent to treat external data as instructions. However, behavior analysis was not run, and the obfuscation issue limits confidence in assessing whether loading this skill materially changes downstream behavior; as a result, confidence is low, and the transparency gap should be resolved before this skill is trusted in sensitive contexts.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around obfuscated or encoded execution path.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Obfuscated or encoded execution path