Fabric.co API skill
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill bundle is benign. All files, including the `SKILL.md` instructions, helper scripts (`fabric.mjs`, `fabric.py`), and API specification (`fabric-api.yaml`), align with the stated purpose of interacting with the Fabric HTTP API. The helper scripts are standard HTTP clients that read the API key from the `FABRIC_API_KEY` environment variable and include a security measure to prevent accidental API key leakage to arbitrary absolute URLs. There is no evidence of prompt injection, data exfiltration, malicious execution, persistence mechanisms, or obfuscation.
