surface-equivalency

Fail

Audited by Snyk on Jul 12, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The https://acme.dev/device URL is a normal OAuth device verification page, but https://acme.dev/install.sh is a direct shell-script download (commonly used with curl | sh) which is a high-risk distribution pattern that can be used to deliver malware.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 12, 2026, 07:28 PM
Issues
1
Security Audit — snyk — surface-equivalency