join-tailnet
Fail
Audited by Snyk on Aug 12, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The official api.tailscale.com endpoints are legitimate, but the api-tailscale.int.exe.xyz host is a non-official, internal-looking domain that impersonates the Tailscale API (including a malformed variant with a trailing brace) and therefore looks suspicious and worthy of caution.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill instructs attaching the
tailscale-apito a VM, SSHing in to start/enable thetailscaledservice and mint auth keys — all actions that modify system state and grant privileged/network authority on the machine.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata