aipa-fundamentals

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). astral.sh/uv/install.sh is a direct .sh installer (commonly used with "curl | sh") hosted on a small third‑party domain and therefore represents a high‑risk distribution vector; aipriceaction.com is the project's website/documentation (low risk) but does not remove the danger of running the remote install script.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill instructs runtime fetching/execution of remote code — e.g., the installation pipe "curl -LsSf https://astral.sh/uv/install.sh | sh" and the runtime use of "uvx aipa-cli@latest" (which fetches and runs the aipa-cli package) — so external content is executed during skill runtime.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 03:40 PM
Issues
2
Security Audit — snyk — aipa-fundamentals