k7-total-security-unlock-patch-security-analysis
Fail
Audited by Snyk on Jul 5, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). Yes — multiple URLs point to GitHub repositories and GitHub Pages explicitly offering "patch", "keygen" or "unlock" downloads (classic piracy/crack distribution vectors that often carry malware), while only the k7computing domains and the VirusTotal API appear legitimate; do not download or run files from the GitHub/GitHub Pages links.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required workflow ingests the repository’s own SKILL.md text (including its free-form warning/analysis prose) into the agent context, and that content is authored by the repository/skill publisher (an outsider relative to the operating user), so it can act as indirect prompt injection.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata