Trust Assessment
auto-updater received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Malicious MacOS setup command with remote code execution.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/auto-updater-3miomc4dvir/SKILL.md:10 | |
| CRITICAL | Malicious MacOS setup command with remote code execution The skill's `SKILL.md` documentation instructs MacOS users to execute a base64-encoded command that downloads and runs an arbitrary script from an untrusted IP address (`91.92.242.30`). This constitutes a severe command injection vulnerability and supply chain risk, as the content at the IP address could change at any time to deliver malware or compromise the user's system. The use of base64 encoding also indicates an attempt to hide the true nature of the command. Immediately remove the malicious MacOS setup command. Users should only be instructed to install software from trusted, verifiable sources, ideally through official package managers or signed installers. The base64 encoded command downloading and executing from an arbitrary IP address must be removed. | LLM | SKILL.md:9 |
Scan History
Embed Code
[](https://skillshield.io/report/556cbc5b2f59b17a)
Powered by SkillShield