OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
This skill implements a 'Generate-then-Execute' pipeline that creates and runs arbitrary Python code on the local system based on user-provided descriptions. This pattern is highly susceptible to prompt injection attacks where a malicious request could cause the agent to generate and execute code that deletes files, exfiltrates sensitive data, or installs malware.
Detected behaviors
1 alert: gptSecurity
No issues
3/3 files flagged
Score: 93/100 · 2 sections analyzed