sota-shell-scripting

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.85). The URLs contain multiple high‑risk indicators: an embedded userinfo credential (https://user:$X@) that leaks secrets, a direct GitHub release binary (releases/download/.../tool-linux-amd64) which can distribute executables and is risky unless the repo is well‑known and the binary is checksum/signed-verified, and an install.sh at example.com which encourages dangerous "download-and-run" behavior; only the generic API endpoint looks innocuous.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 17, 2026, 02:07 PM
Issues
1
Security Audit — snyk — sota-shell-scripting