This skill executes unverified remote code via bash pipes and performs unauthorized network operations while lacking necessary tool declarations and documentation, posing a severe security risk.
npx skills add https://github.com/anthropics/knowledge-work-pluginsRemote code download and execution detected
curl -s https://get.nextflow.io \| bash
The skill provides a command to pipe a remote script directly into bash, which is a common vector for executing arbitrary, unverified code.
curl -s https://get.nextflow.io | bash
SKILL.md links to "references/geo-sra-acquisition.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/geo-sra-acquisition.md](references/geo-sra-acquisition.md)
SKILL.md links to "references/pipelines/atacseq.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/pipelines/atacseq.md](references/pipelines/atacseq.md)
SKILL.md links to "references/pipelines/rnaseq.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/pipelines/rnaseq.md](references/pipelines/rnaseq.md)
SKILL.md links to "references/pipelines/sarek.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/pipelines/sarek.md](references/pipelines/sarek.md)
SKILL.md links to "references/troubleshooting.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/troubleshooting.md](references/troubleshooting.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/anthropics/knowledge-work-plugins/nextflow-development)<a href="https://mondoo.com/ai-agent-security/skills/github/anthropics/knowledge-work-plugins/nextflow-development"><img src="https://mondoo.com/ai-agent-security/api/badge/github/anthropics/knowledge-work-plugins/nextflow-development.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/anthropics/knowledge-work-plugins/nextflow-development.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.