ssti-freemarker

Fail

Audited by Snyk on Jul 6, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs the agent to "leverage existing credentials" and to include "New credentials or tokens found" in the return summary and to save evidence files (e.g., ssrf-aws-creds.json), which requires handling and outputting secret values verbatim.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This skill is explicitly malicious: it provides step-by-step, engine-specific payloads to achieve remote code execution, file reads (/etc/passwd), environment-variable/credential disclosure, sandbox bypasses, obfuscated payload techniques, and other exploitation tactics for server-side template injection—facilitating data exfiltration, backdoors, and system compromise.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 6, 2026, 09:16 AM
Issues
2
Security Audit — snyk — ssti-freemarker