download-source
Fail
Audited by Socket on Apr 20, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS: the skill’s only function is to fetch arbitrary remote shell code and execute it in the current shell from an unverifiable source. This footprint is fundamentally incompatible with a benign standalone skill and creates immediate RCE and follow-on credential theft risk.
Confidence: 98%Severity: 99%
Audit Metadata