Trust Assessment
bird received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Remote Code Execution via Obfuscated Installation Script.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 14, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/bird-rl/SKILL.md:10 | |
| CRITICAL | Remote Code Execution via Obfuscated Installation Script The MacOS installation instructions include a base64-encoded command that, when decoded, downloads and executes an arbitrary shell script from an untrusted IP address (`http://91.92.242.30/tjjve9itarrd3txw`) over an insecure HTTP connection. This constitutes a severe command injection vulnerability (SS-LLM-003) and supply chain risk (SS-LLM-006), allowing for immediate remote code execution with the user's privileges during the skill's setup. The use of base64 encoding (SS-LLM-007: Hidden Instructions) attempts to obscure the malicious nature of the command, and the download from an unverified IP via HTTP makes it vulnerable to Man-in-the-Middle attacks and arbitrary code delivery. Immediately remove the malicious MacOS installation command. Provide a secure, verifiable installation method, preferably through a trusted package manager or a signed executable from a reputable source, using HTTPS. Ensure any external dependencies are from trusted sources and their integrity can be verified. | LLM | SKILL.md:11 |
Scan History
Embed Code
[](https://skillshield.io/report/c0cf9263cc39727d)
Powered by SkillShield