bug-bounty
Fail
Audited by Snyk on Jun 1, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). The list contains many direct-download/install-script URLs (raw.githubusercontent.com install.sh, GitHub releases linking binaries/tar.xz), unknown/small GitHub repos and personal/attacker-controlled domains (evil.com, attacker.com, burpcollaborator endpoints), and other direct executable/script references — which are high-risk sources for malware distribution if executed without verification.
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata