sota-devsecops
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). Most entries are legitimate supply‑chain, registry, or internal service endpoints (npm, PyPI, Sigstore/Rekor, GitHub workflow identities, internal proxies, OIDC token issuer, Kubernetes service) and are not themselves malicious, but the direct-download links to unknown domains (releases.example.com/tool-1.4.2-linux-amd64.tgz and install.example.com/tool.sh) are unverified direct installers and represent high‑risk distribution vectors that could deliver malware if not validated.
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata