gophish

Fail

Audited by Snyk on Apr 16, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly shows and instructs embedding credentials verbatim (e.g., curl -H "Authorization: Bearer API_KEY", SMTP username/password configuration, and a default admin:gophish credential), so the agent would be expected to handle and output secret values directly.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content is explicitly designed to create and operate targeted phishing campaigns (SMTP relay setup, cloned landing pages with "Capture Credentials", tracking pixels, domain spoofing and deliverability tips), which directly facilitate credential theft and data exfiltration and therefore is intentionally malicious.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs cloning target login pages in the Campaign Workflow ("Landing Page — clone target login page") and references resources (references/campaign-setup.md) implying the agent will fetch and ingest arbitrary public websites' content to build landing pages, which is untrusted third-party content that could influence actions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). The skill explicitly instructs setting up system-level infrastructure (binding to port 443, using cert files under /etc/letsencrypt, configuring Postfix/SMTP and DNS/DKIM) which implies modifying privileged system files and services and therefore pushes the agent toward actions that can change/compromise the machine state.

Issues (4)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 16, 2026, 08:20 PM
Issues
4
Security Audit — snyk — gophish