adversarial-review
Fail
Audited by Snyk on May 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The prompt explicitly instructs spawned agents to "always pass mode: 'bypassPermissions'", directing circumvention of permission controls and overriding tool/frontmatter defaults—an instruction that changes agent behavior outside the stated scope of adversarial code review and is therefore a prompt-injection risk.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill contains an explicit, deliberate instruction to spawn agents with mode: "bypassPermissions" (i.e., bypassing permission prompts and security controls), which is an intentional attempt to circumvent protections and enable unattended/unauthorized privileged actions.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs spawned agents to run with mode: "bypassPermissions", instructing the agent to bypass permission prompts/security mechanisms which can enable unauthorized system state changes and compromise the machine.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata