ship-software

Fail

Audited by Snyk on Jul 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These URLs point to an individual GitHub repository (Lua2147/claude-toolkit-catalog) which, while hosted on GitHub, is an unvetted third‑party source and therefore represents a supply‑chain risk for distributing executables or toolkits unless you verify the repo's provenance, activity, and contents first.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The SOP explicitly requires running "git clone https://github.com/Lua2147/claude-toolkit-catalog.git" at runtime to install a toolkit that provides skills, agents, and commands which can control agent prompts and execute code, making this an external runtime dependency.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 15, 2026, 12:57 PM
Issues
2
Security Audit — snyk — ship-software