write-workflow
Fail
Audited by Snyk on Aug 20, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). Both URLs are external GitHub repositories from individual accounts used as install targets (npx/git clones) — unvetted third‑party code can execute during install and is commonly used to distribute malicious packages, so they should be treated as suspicious until vetted.
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata