over-permissioned

Fail

Audited by Snyk on Sep 1, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The skill requests access to sensitive files and directories such as SSH keys, AWS credentials, and password files that are entirely unrelated to organizing local media and document files.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill prompt explicitly instructs the agent to run commands using sudo to operate on system-wide directories and accesses sensitive system and configuration files.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 1, 2026, 11:05 AM
Issues
2
Security Audit — snyk — over-permissioned