od-contribute
Fail
Audited by Snyk on Aug 2, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill explicitly tells the agent to "surface the printed install / auth hint verbatim" (which could contain tokens) and to substitute an environment variable (
$OD_DISCORD_INVITE) directly into rendered PR bodies, requiring the LLM to output verbatim secret-like values.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). These URLs include direct downloads of code (a GitHub tarball and a raw .sh script) that the installer fetches and, in one documented usage, pipes to bash — a high-risk pattern because executing remotely-hosted scripts or archives can deliver malware if the source is compromised or untrusted.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime, the required workflow uses
gh search issues "<keywords>" --repo "$TARGET_REPO"inscripts/create-issue.sh(viaod-contributeStep 3d.4/3d.5) which causes the agent to ingest outsider-authored free text from existing GitHub issue titles/URLs returned by the search results before it renders and submits a new bug report.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The installer includes an explicit agent-run command that fetches and pipes a remote script to bash (curl -sSL https://raw.githubusercontent.com/nexu-io/open-design/main/.claude/skills/od-contribute/install.sh | bash), which is a runtime remote-script-execution pattern that would let external content control execution.
Issues (4)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata