auditing-config-and-build-hygiene
Fail
Audited by Snyk on Jul 6, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). Two direct .sh links (https://internal.example/toolchain.sh and https://deps.example/setup.sh) are executable installers hosted on untrusted/example domains and match high-risk patterns (remote shell scripts with no pin/checksum) that are commonly used to deliver malware or supply-chain attacks.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow is to audit a “build/config scan” (e.g., CI YAML, Dockerfiles, scripts, flags) that is provided as free-form text at runtime, which is outsider-authored content when it comes from the reviewed repo rather than the operating user’s own prompts/files.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata