soia-env-antigravity-cli-install
Fail
Audited by Snyk on Aug 6, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). These URLs include a direct install script (https://antigravity.google/cli/install.sh) and a Google Cloud Run hostname used as the manifest/auto-updater base (https://antigravity-cli-auto-updater-974169037036.us-central1.run.app), both of which are non-standard/uncommon distribution endpoints for installers and therefore present a higher risk of delivering malicious installers or manifests.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill explicitly downloads and then executes the remote installer script at runtime (it says to download and run https://antigravity.google/cli/install.sh), which is a required runtime dependency that executes remote code.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata