taste-skill: why it is not safe to use
taste-skill passed our security and privacy review with no material issues found in the reviewed repository.
What we found
Our review of `Leonxlnx/taste-skill` passed with a score of 92/100. In the reviewed repository, we did not find hidden or disguised instructions. The skill states its scope, triggers, and behavior openly in `SKILL.md`. We also did not find evidence that it sends user data to undisclosed third parties. The repository appears to consist of prompt content plus a local path helper script.
We found no hardcoded credentials, API keys, or tokens in the files we reviewed. We also did not find delete, overwrite, publish, or other irreversible shell actions, and we saw no instructions to perform those actions without confirmation. The files were plain text and readable, with no encoded, minified, or review-evasive payloads. We also found no runtime remote code fetch or execution, no access to environment variables or stored credentials, and no signs of privilege escalation or permission changes.
What to do instead
If you use this skill, keep normal safeguards in place: review future updates, limit access to only the files it needs, and verify any package or link suggestions before acting on them.
Source: https://github.com/Leonxlnx/taste-skill
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.