token-burner

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). This is a GitHub repository from an unfamiliar username that instructs users to install/execute the provided skill (via npx or cloning into agent skill folders), so although it's hosted on GitHub (not an immediate binary download) it is potentially suspicious because it could execute arbitrary code and the account/repo reputation is unknown.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 11:45 AM
Issues
2
Security Audit — snyk — token-burner