SkillBOM performs static inspection and does not execute skill scripts. A clean report is not a guarantee that a skill is safe. Review high-impact skills manually and run untrusted code only in a disposable sandbox.
Please report vulnerabilities privately through GitHub's security advisory feature. Do not include live credentials or sensitive user data in a report.