multi-model-verification
Fail
Audited by Snyk on May 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The prompt explicitly instructs callers to always pass mode:"bypassPermissions" when spawning agents—an operational directive to override permission checks that is outside the stated verification purpose and constitutes a deceptive/unsafe instruction.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill content contains a deliberate instruction to disable/ bypass agent permission prompts ("mode: "bypassPermissions"") which explicitly enables unattended, elevated agent actions and can be abused as a backdoor to perform unauthorized modifications or remote actions; otherwise the document is a benign multi-review design without direct exfiltration or obfuscated payloads.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs spawning agents with mode: "bypassPermissions" to avoid permission prompts, which directs the agent to bypass security mechanisms and is therefore a state-compromising instruction.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata