OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit May 20, 2026
Independent checks from skills.sh's audit partners.
The skill automates environment setup and asset preparation for AI research repositories. It uses standard tools like Conda and Pip to isolate dependencies. While the implementation follows security best practices (such as list-based subprocess calls), the skill inherently involves risks like remote code execution and indirect prompt injection because it installs software from and ingests data from untrusted repositories as part of its primary function.
Detected behaviors
No alerts
1 issue