deep-research
Fail
Audited by Snyk on Jul 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). Two GitHub URLs point to an unverified third‑party organization (199-biotechnologies) that the skill instructs users to clone or install (git clone / brew tap), which is a common vector for distributing untrusted binaries or installers and therefore raises a high-risk flag; other listed links are documentation, placeholders, or benign sources.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes—at runtime the skill’s required RETRIEVE phase uses WebSearch/WebFetch/search-cli to ingest public web page text (outsider-authored free text) into the agent’s working context for later synthesis/packaging.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata