@jaypie/tildeskill
Provides a storage abstraction for skill documents with markdown support, enabling easy management and retrieval of skills for AI assistants.
Install this skill
or
80/100
Security score
The @jaypie/tildeskill skill was audited on Feb 17, 2026 and we found 4 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
medium line 64
Template literal with variable interpolation in command context
SourceSKILL.md
| 64 | skills.forEach(s => console.log(`${s.alias}: ${s.description}`)); |
medium line 269
Template literal with variable interpolation in command context
SourceSKILL.md
| 269 | return skills.map(s => `${s.alias}: ${s.description}`).join("\n"); |
medium line 272
Template literal with variable interpolation in command context
SourceSKILL.md
| 272 | return skill?.content ?? `Skill "${alias}" not found`; |
medium line 169
Path traversal pattern
SourceSKILL.md
| 169 | isValidAlias("../../etc"); // false (path traversal) |
Scanned on Feb 17, 2026
View Security DashboardInstall this skill with one command
/learn @finlaysonstudio/jaypie-tildeskill