📦
Audit History
bot-store-marketplace - 1 audit
Audit version 1 Latest
Oct 3, 2026, 12:54 PM
One finding is confirmed: the installation command executes an unpinned external package and retrieves upstream skill content without an immutable reference. Sixteen findings are false positives involving Markdown tool names, task-related URLs, and checkout terminology. No evidence found of prompt injection, credential collection, unauthorized payment, or system reconnaissance in the reviewed skill.
1
Files scanned
63
Lines analyzed
3
Review items
0
False positives ignored
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Medium
Ruby/shell backtick execution
Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill bot-store-marketplace`.
The backticks are Markdown, but the enclosed pnpm dlx installation command executes an unpinned external package and retrieves upstream skill content. This creates a concrete supply-chain execution risk, although no malicious payload is shown.
Risk Factors
⚙️ External commands (9)
🌐 Network access (5)
Audited by: codex