infra-security

Fail

Audited by Snyk on Jun 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The GitHub URL is pinned to a release on a well-known host (low risk), but the other two are untrusted module sources — one served over plain HTTP (high risk: MITM/supply‑chain tampering) and the other is an unpinned HTTPS host on a custom domain (supply‑chain risk); treat those two as suspicious.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 24, 2026, 11:35 AM
Issues
1
Security Audit — snyk — infra-security