analytics

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (medium risk: 0.30). run.sh contains an explicit install instruction that pipes a curl download to sh: "curl -LsSf https://astral.sh/uv/install.sh | sh", which downloads and executes a third-party installer from astral.sh (download-and-execute from an external domain under third-party control is a risky pattern though not proven malicious).

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). sourceText exposure occurs when the outsider supplies a dataset file path to commands like ./run.sh describe <file>/chart <file>/insights <file>, which load and ingest the file’s free-form JSON/CSV/JSONL text at runtime and can be further rendered/used for outputs.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 26, 2026, 06:02 PM
Issues
2
Security Audit — snyk — analytics