Security Report: Semgrep Static Analysis
Automated security scan detected 10 errors and 2 warnings in this skill. Review the findings below before installing.
Latest Scan
Findings
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Shell command execution detected: os.system(
Shell command execution patterns detected
Shell command execution detected: os.system(
Shell command execution patterns detected
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Dynamic code execution via eval(): eval(
Dynamic code execution via eval() or similar
Command injection pattern: `todoruleid`
Command injection patterns detected
Possible base64-encoded content detected: handbook/refs/heads/main/content/docs/static
Possible encoded or obfuscated content
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/semgrep/semgrep-docs/refs/heads/main/docs/w...
URL found in skill content: https://raw.githubusercontent.com/trailofbits/testing-handbook/refs/heads/mai...
Disclaimer: Automated scanning catches known patterns but cannot guarantee a skill is safe. Always review the source code before installing community skills. Learn more about our security process.