OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
The skill is vulnerable to command injection because it interpolates user-provided repository names and questions directly into shell commands. It also depends on the runtime download of an external package from npm and is susceptible to indirect prompt injection from unvetted GitHub content.
Detected behaviors
No alerts
No issues
1 file scanned · No issues
Score: 93/100 · 2 sections analyzed