token-burner
Fail
Audited by Snyk on Jun 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). This is a GitHub repository from an unfamiliar username that instructs users to install/execute the provided skill (via npx or cloning into agent skill folders), so although it's hosted on GitHub (not an immediate binary download) it is potentially suspicious because it could execute arbitrary code and the account/repo reputation is unknown.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata