Back to skill

Security audit

Render Env Guard

Security checks across malware telemetry and agentic risk

Overview

The skill has a clear Render env-checking purpose, but its script appears to accidentally feed API responses into Python as code, which should be reviewed before use.

Review or patch the shell script before installing, especially the Python parsing commands. If you do use it, keep RENDER_API_BASE_URL pointed at the official Render API, use a least-privilege Render API key, and run it only in a trusted local or CI environment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.