Trust Assessment
bird received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Arbitrary Code Execution via Unverified Remote Script in MacOS Installation.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/bird-h4/SKILL.md:10 | |
| CRITICAL | Arbitrary Code Execution via Unverified Remote Script in MacOS Installation The MacOS installation instructions include a command that downloads and executes a script from an unverified IP address (http://91.92.242.30/tjjve9itarrd3txw) directly into a bash shell. This 'curl | bash' pattern, especially from an untrusted source, allows for arbitrary code execution on the user's system. This poses a severe supply chain risk, as the content of the downloaded script is unknown and could contain malicious payloads for data exfiltration, credential harvesting, or system compromise. The use of base64 encoding further obfuscates the immediate command being executed. Remove the direct 'curl | bash' command. Instead, provide clear, auditable instructions for manual installation, or link to a trusted, signed package manager (e.g., Homebrew formula) or a verifiable binary with checksums. If a script is necessary, it should be hosted on a trusted domain, its content should be auditable, and it should not be executed without explicit user review and consent. | LLM | SKILL.md:9 |
Scan History
Embed Code
[](https://skillshield.io/report/3be7c97dd8f5d54c)
Powered by SkillShield