Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
This skill provides a framework and templates for generating AI agents. While the skill itself does not contain malicious code, the agents it generates are designed to process untrusted external data (like source code and pull requests) and are equipped with file modification capabilities (Write tool). This creates a high-risk surface for Indirect Prompt Injection, as there are no built-in safeguards or sanitization mechanisms defined in the architectural templates.
Detected behaviors
No alerts
No issues
7/7 files flagged
Score: 93/100 · 2 sections analyzed