sota-code-security
Fail
Audited by Snyk on Aug 5, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Most URLs are benign documentation, but the list includes obfuscated/attacker-controlled examples (http://expected.com@evil.com/, https://evil.com/?q=) and a loopback address (http://127.0.0.1/) which are classic SSRF/exfiltration/obfuscation indicators and could be abused to deliver or trigger malware
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata