GInstall OneClick

PassAudited by VirusTotal on May 15, 2026.

Findings (1)

The skill provides a wrapper for the 'ginstall' CLI to automate cloning and executing GitHub repositories, which constitutes a high-risk capability involving shell and network access. While the instructions include security warnings against sharing GITHUB_TOKEN and use quoted shell arguments to prevent injection, the automated execution nature (using the --yes flag) and a discrepancy between the project URLs in SKILL.md and README.md (ginstall-oneclick vs YunzhouLi-hub) warrant a suspicious classification per the provided criteria regarding high-risk behaviors.