minecraft-security-analysis

Fail

Audited by Snyk on May 23, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.90). Although several entries are legitimate Minecraft mod platforms (Modrinth, CurseForge, Fabric, Forge, OptiFine), the list also contains a direct .exe on an untrusted host (http://malicious-site.com/stealer.exe) and a suspicious GitHub repo/username (ochoaochoa330-design/Aegis-V4-Client-2026) that appears to link to external hosting/typosquatting, so the overall set represents a high-risk download surface likely usable for malware distribution.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The repository content and included examples strongly indicate deliberate malicious intent—misleading "cracked" client distribution with external download links, obfuscated payload/download-and-execute Java code, Discord token-stealer patterns, and string/URL-hiding techniques consistent with data exfiltration, backdoor/remote-code-execution, credential theft, and supply-chain abuse.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 23, 2026, 10:50 PM
Issues
3
Security Audit — snyk — minecraft-security-analysis