OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail3 providerslatest audit Mar 18, 2026
Independent checks from skills.sh's audit partners.
This skill instructs the agent to automatically discover and execute commands defined in a project's `Taskfile.yml`. This creates a high risk of indirect prompt injection, as an attacker can place malicious commands in the configuration file of a repository that the agent will then execute as part of its development workflow.
Detected behaviors
No alerts
No issues