Security audit
Render Env Guard
Security checks across malware telemetry and agentic risk
Overview
The skill has a clear Render env-checking purpose, but its script appears to accidentally feed API responses into Python as code, which should be reviewed before use.
Review or patch the shell script before installing, especially the Python parsing commands. If you do use it, keep RENDER_API_BASE_URL pointed at the official Render API, use a least-privilege Render API key, and run it only in a trusted local or CI environment.
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
