vite-plus

Fail

Audited by Snyk on Aug 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The "Companion check" instructs the agent to run local filesystem commands (ls ~/.claude/skills/ ~/.agent/skills/ ...) and offer/install other skills, which directs the agent to access and act on the user's local environment—behavior that is outside the Vite+ documentation/help purpose and can expose or modify local state.

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 1.00). The skill instructs users to pipe a remote installer into a shell/PowerShell from the vite.plus host (curl -fsSL https://vite.plus | bash and irm https://vite.plus/ps1 | iex), which is a high-risk pattern and the domain differs from the main docs site (viteplus.dev), raising typosquatting/malicious-host concerns.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill's installation commands fetch and immediately execute remote scripts from https://vite.plus and https://vite.plus/ps1 (curl ... | bash and irm ... | iex), which runs remote code at install/runtime.

Issues (3)

E004
CRITICAL

Prompt injection detected in skill instructions.

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 10, 2026, 02:12 PM
Issues
3
Security Audit — snyk — vite-plus