swift-concurrency
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecurityes/index.md
MEDIUMSecurityMEDIUM
es/index.md
This fragment is a high-risk supply-chain/prompt-injection installer: it downloads unverified Markdown instruction/skill content from a hardcoded remote URL and persists it into user and project directories used by AI coding agents. While no classic malware actions (shell/exfiltration) are shown in the snippet, the unvalidated remote-to-agent-instruction flow makes altered or malicious remote content a credible security threat.
Confidence: 75%Severity: 78%
Audit Metadata