vite-plus
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The "Companion check" instructs the agent to run local filesystem commands (ls ~/.claude/skills/ ~/.agent/skills/ ...) and offer/install other skills, which directs the agent to access and act on the user's local environment—behavior that is outside the Vite+ documentation/help purpose and can expose or modify local state.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). The skill instructs users to pipe a remote installer into a shell/PowerShell from the vite.plus host (curl -fsSL https://vite.plus | bash and irm https://vite.plus/ps1 | iex), which is a high-risk pattern and the domain differs from the main docs site (viteplus.dev), raising typosquatting/malicious-host concerns.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill's installation commands fetch and immediately execute remote scripts from https://vite.plus and https://vite.plus/ps1 (curl ... | bash and irm ... | iex), which runs remote code at install/runtime.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata