deep-research

Fail

Audited by Snyk on Jul 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Two GitHub URLs point to an unverified third‑party organization (199-biotechnologies) that the skill instructs users to clone or install (git clone / brew tap), which is a common vector for distributing untrusted binaries or installers and therefore raises a high-risk flag; other listed links are documentation, placeholders, or benign sources.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Yes—at runtime the skill’s required RETRIEVE phase uses WebSearch/WebFetch/search-cli to ingest public web page text (outsider-authored free text) into the agent’s working context for later synthesis/packaging.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 10, 2026, 12:23 PM
Issues
2
Security Audit — snyk — deep-research