Skylv Team Workflow Automation

PassAudited by VirusTotal on May 4, 2026.

Findings (1)

The skill bundle contains instructions in SKILL.md that direct the AI agent to clone an external GitHub repository (github.com/jnMetaCode/agency-agents-zh) and execute a shell script (install.sh). This pattern facilitates a supply chain risk by encouraging the agent to download and run unverified remote code on the host system. While no explicitly malicious payload is present in the provided files, the instruction for the agent to perform a 'git clone' followed by script execution is a high-risk behavior that could be used for remote code execution.