websecurityacademy-solutions

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These URLs are not direct official download links but include attacker-controlled hosts, exploit servers (e.g. malicious.dtd, attacker.com, Burp Collaborator/OAST placeholders), internal/local endpoints and obfuscated IP forms used for SSRF/XXE/exfiltration — making them highly suspicious as vectors for delivering or triggering malicious payloads even though they are not explicit .exe/.msi download URLs.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains explicit exploit payloads and step-by-step instructions that enable data exfiltration (cookies, tokens, files), credential theft, SSRF/XXE/command-injection leading to remote code execution and OOB callbacks — capabilities clearly usable for malicious abuse outside authorized testing.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 01:53 AM
Issues
2
Security Audit — snyk — websecurityacademy-solutions