production-grade
Fail
Audited by Snyk on May 1, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The prompt includes hidden/overriding behaviors—e.g., a "DryRunContext" described as "system prompt injection" and multiple "silently execute" auto-initialization/update shell commands that alter system state or inject prompts without explicit user consent—behaviors that manipulate agent/system context and perform side-effectful operations beyond the stated orchestration description, so this constitutes prompt injection.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to ingest and research arbitrary public web sources (e.g., Research Mode Phase 2 "Source Ingestion" using NotebookLM with "Add source URLs" and "nlm research start --mode deep", and optional crawl4ai web crawling in the auto-install steps), and those ingested third‑party pages are used to drive research gates and plan/execution decisions — exposing the agent to untrusted web content that can influence its actions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill performs a runtime auto-update check that reads https://raw.githubusercontent.com/buiphucminhtam/forgewright/main/VERSION and, if updated, can git clone --depth 1 https://github.com/buiphucminhtam/forgewright.git and replace local skill files—i.e., it fetches and installs remote code at runtime which can change agent prompts/behavior and execute code.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata