chronology-builder-andrew-bird

Fail

Audited by Snyk on Jul 30, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Both URLs point to GitHub repositories hosted under a single, personal/unknown account and are recommended for direct git clone/install in the README—GitHub code from low‑reputation personal accounts can be used to distribute malicious code and lacks the usual trust signals.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md describes extracting “dated events” from user-provided disclosure documents and other user-supplied sources (Steps 3–4), meaning outsider-authored text submitted via those paths is directly ingested after the CPR 31.22/privilege checks.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 30, 2026, 07:33 PM
Issues
2
Security Audit — snyk — chronology-builder-andrew-bird