codex-first-customer-finder-skill
Fail
Audited by Snyk on Jul 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The manual-install git clone points to a third-party GitHub repo (https://github.com/Kappaemme-git/codex-first-customer-finder-skill.git) from an unknown username which is a potential unverified distribution source for code — other listed URLs are placeholders or an official site and are low risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow explicitly searches “public sources” for demand/pain/timing signals and produces evidence-backed prospect shortlists with “source links,” which implies runtime ingestion of outsider-authored free text from public web pages/forums/Repos into the agent’s LLM context for analysis.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata