task-monitor
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (medium risk: 0.30). The repository's install script (install_services.sh) recommends installing "uv" by piping a remote installer from https://astral.sh/uv/install.sh (curl -LsSf https://astral.sh/uv/install.sh | sh), which is an external script download executed directly.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Outsider-authored free text can be ingested into the skill at runtime via HTTP requests to
POST /tasks/{name}/state(FastAPI endpoint writes the request JSON to a task state file, which the TUI/API later reads and renders).
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill instructs installing and managing systemd service units (via ./install_services.sh and systemctl --user), which modifies system service configuration and thus alters the machine's state.
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata