AlemTuzlak Skills: why it is not safe to use
AlemTuzlak Skills passed our review; we found no hidden prompts, credential access, undisclosed data sharing, or unsafe destructive steps.
What we found
Our review of the inspected repository materials did not identify a security or privacy issue that would block listing. We reviewed the README, AGENTS.md, and CLAUDE.md and did not find hidden or misleading prompt instructions intended to override user intent. We also did not find hardcoded secrets, instructions to access unrelated credentials, or signs of privilege escalation.
The documented workflows focus on local file generation, local transcription and rendering, and an optional GitHub release action using the user's connected account. Based on the reviewed materials, we did not find evidence of undisclosed third party data transfer, covert runtime fetching, remote code execution, or irreversible destructive commands without confirmation. The repository also describes approval points around more sensitive actions such as review loops and optional cleanup.
What to do instead
If you use this skill, keep the same practical safeguards you would use with any automation. Review prompts and generated files before publishing or releasing them, confirm optional GitHub actions before running, and inspect local scripts and Docker build steps in your own environment. If your use case involves sensitive data, prefer test inputs first and verify where outputs are written and which tools are invoked.
Source: https://github.com/AlemTuzlak/skills
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.