tzai-xhs-cover
Fail
Audited by Snyk on Aug 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The URL points to a GitHub repository owned by an individual account and the skill instructs installing/running code (via npx/skills), which can execute arbitrary code and is a common malware distribution vector when sourced from unknown/unverified authors.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md for
/tzai-xhs-coverroutes “Slash arguments / remaining user text” as a--promptto thetzai-imageengine for image generation, so outsider-authored free text is directly ingested by the runtime as prompt content.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata