evilginx2
Fail
Audited by Snyk on Apr 16, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs capturing session cookies/tokens and copying or embedding them verbatim into commands (e.g., curl -H "Cookie: <captured_cookie>") and to display session tokens, which requires the LLM to handle and output secrets directly.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is explicitly malicious: it documents and instructs use of a reverse‑proxy phishing framework (Evilginx2) to perform adversary‑in‑the‑middle attacks that capture credentials and session cookies, bypass MFA, and enable account takeover and covert exfiltration of authentication tokens.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly describes proxying real third-party sites ("Evilginx2 proxies the real site" and commands like
phishlets enable <name>which "starts proxy") and captures session content from those public sites as part of its runtime workflow, exposing the agent to untrusted third-party web content that can influence actions.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata