post-release-followup
Fail
Audited by Snyk on May 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The prompt contains explicit, operational instructions to evade auditing and permission controls (write-to-/tmp workaround and "always pass mode: 'bypassPermissions'") that instruct bypassing security checks and are not required as part of the stated follow-up analysis purpose, so this is a hidden/deceptive instruction.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content includes explicit instructions to bypass permission checks and auditing (writing via /tmp and forcing Agent mode "bypassPermissions") to hide file writes and override prompts, which is an intentional mechanism to evade security controls and enables backdoor-like behavior and unauthorized modifications.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and parses user-generated GitHub content (e.g., via
gh issue list --label verify-done --state open --json ...andgh api repos/{owner}/{repo}/pulls/{pr_number}/comments) as part of its required workflow and then uses those findings to decide and delegate actions, so untrusted third‑party content can materially influence tool behavior.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs agents to bypass permission checks (e.g., "always pass mode: 'bypassPermissions'") and to use an audited-avoiding copy pattern into the sensitive .claude/ outputs path, which directs circumventing security mechanisms and modifying machine state.
Issues (4)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata