OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
The skill contains instructions that result in the exposure of sensitive API keys in the agent's logs and history. It also accesses configuration files in the user's home directory and includes destructive commands like 'rm -rf'. The lack of sanitization when reading local configuration files creates a high risk of indirect prompt injection, as malicious project files could manipulate the agent's diagnostic behavior.
Detected behaviors
No alerts
No issues
1/1 file flagged
Score: 93/100 · 2 sections analyzed