skill-iter-tune

Fail

Audited by Snyk on Jul 2, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The orchestrator routinely sends full skill files and produced artifacts to external LLM endpoints (ccw cli → Claude/Gemini) and runs a general-purpose Agent that can automatically modify local skill files, which together create clear high-risk patterns for data exfiltration and for introducing backdoors or malicious changes (supply‑chain abuse), plus the potential to leak credentials if any secrets are present in the project files.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 2, 2026, 06:13 AM
Issues
1
Security Audit — snyk — skill-iter-tune