ssti-freemarker
Fail
Audited by Snyk on Jul 6, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs the agent to "leverage existing credentials" and to include "New credentials or tokens found" in the return summary and to save evidence files (e.g., ssrf-aws-creds.json), which requires handling and outputting secret values verbatim.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill is explicitly malicious: it provides step-by-step, engine-specific payloads to achieve remote code execution, file reads (/etc/passwd), environment-variable/credential disclosure, sandbox bypasses, obfuscated payload techniques, and other exploitation tactics for server-side template injection—facilitating data exfiltration, backdoors, and system compromise.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata