Audit History
nature-downloader - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Aug 18, 2026, 08:34 AM
Most scanner matches are documentation, tests, fixed imports, status constants, or expected local file operations. Confirmed risks include CAPTCHA circumvention, unrestricted authenticated fetching, arbitrary credential forwarding, command-line secret exposure, and unbounded direct downloads. No prompt injection text was found. Static review was capped at 400/766 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (6)
Capability review items (7)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (50)
🔑 Env variables (50)
📁 Filesystem access (50)
⚙️ External commands (50)
Aug 18, 2026, 08:34 AM
Most scanner matches are documentation, tests, fixed imports, status constants, or expected local file operations. Confirmed risks include CAPTCHA circumvention, unrestricted authenticated fetching, arbitrary credential forwarding, command-line secret exposure, and unbounded direct downloads. No prompt injection text was found. Static review was capped at 400/766 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (6)
Capability review items (7)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.