web3-hunt-foundation
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.30). This skill is a dual-use bug‑bounty guide that gives detailed, actionable instructions for identifying and exploiting Web3 smart‑contract vulnerabilities (e.g., how to "steal, freeze, or destroy", exact transaction steps, flash‑loan vectors), which could facilitate attacks despite a security-research framing.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly centered on Web3 financial operations and attacker actions involving on-chain transactions. It instructs building exact transaction sequences ("CALL: Exact transactions, exact order, exact function names"), lists required setup including "wallet, capital", and repeatedly references fund-moving functions and impacts (deposit(), withdraw(), mint/burn, claim/harvest, flash loans, stealing deposits, emergencyWithdraw). These are specific crypto/blockchain execution actions (wallets, transactions, flash loans, token mint/burn) rather than generic tooling, so it grants direct financial execution capability in a web3 context.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata