harness-eval
Fail
Audited by Snyk on May 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). Yes — the prompt includes explicit instructions on how to bypass sensitive-path checks and audit controls (write to /tmp then copy into .claude/), which are deceptive, security-evasion steps unrelated to the stated evaluation purpose.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content includes explicit, deliberate instructions to bypass sensitive-path permission and auditing controls (write to /tmp then use an unaudited /tmp shell script to copy into .claude/outputs), which enables unauthorized filesystem writes and stealthy persistence—this is a high-risk backdoor/abuse pattern even though no external exfiltration or remote-control code is present.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). The skill explicitly documents and instructs a sensitive-path permission bypass (write to /tmp then run a /tmp script that silently copies into .claude/outputs), which is a direct security-bypass instruction that modifies filesystem state and risks compromising the machine.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata