Skip to content
Discussion options

You must be logged in to vote

Thanks for reporting this — I checked the exact object currently on main, not just the filename or rendered GitHub page.

I found no Trojan payload in skills/buywhere-product-catalog/SKILL.md. The directory contains only that single file. It is a 4,427-byte UTF-8 Markdown document: no executable or binary content, no scripts, no ANSI escape sequences or hidden control characters, and no bundled assets. Its two fenced examples are explicitly inert text examples. The repository's documentation-security scan also passes.

Current identifiers:

  • Git blob: f868b69c41aca1cb39a4fc3ffc6411fe53d0f120
  • SHA-256: 9fe27450068f341f2ab595aaf0616ae493e1c672136940aabe5d969b07cebc52

The file has not changed s…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by sickn33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
question Further information is requested
2 participants