write-workflow

Fail

Audited by Snyk on Aug 20, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Both URLs are external GitHub repositories from individual accounts used as install targets (npx/git clones) — unvetted third‑party code can execute during install and is commonly used to distribute malicious packages, so they should be treated as suspicious until vetted.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 20, 2026, 07:39 AM
Issues
1
Security Audit — snyk — write-workflow