Network Security
Fail
Audited by Snyk on Apr 11, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This content explicitly documents offensive techniques with clear abuse patterns — credential theft (brute force, fetching exposed keys, searching bash history), tunneling/remote forwarding for pivoting or covert access (ssh -D, ssh -R, proxychains), evasion strategies (rate limiting, spreading attempts across IPs), and post‑exploitation persistence/credential harvesting (searching authorized_keys, id_rsa) — all of which can be used as backdoors or data‑exfiltration mechanisms if misused.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent/operator to fetch and analyze untrusted third-party content (e.g., Shodan searches and host data in references/reconnaissance.md and remote file retrieval via curl in references/protocol-testing.md and references/ssh-penetration sections), so the agent would ingest public web/social-hosted content that can change scanning/exploitation decisions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata