Security Scanning Tools

Fail

Audited by Snyk on Apr 15, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt includes commands that embed an API key directly on the command line (e.g., zap.sh -daemon -port 8080 -config api.key=<your_key>), which requires substituting a secret verbatim into generated commands and thus poses an exfiltration risk.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's core workflow explicitly instructs crawling and scanning external websites and hosts (e.g., "Phase 3: Web Application Scanning Tools" with zap-cli quick-scan https://target.com and Burp Spider/Proxy steps) so the agent will fetch and interpret untrusted third-party web content which can influence subsequent scanning/exploitation actions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill repeatedly instructs privileged, state-changing actions on the host (sudo package installs, systemctl service start, enabling monitor mode, running scanners/exploit frameworks and remediation scripts) which push an agent to modify the machine's state and require/encourage elevated privileges.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 15, 2026, 06:10 PM
Issues
3
Security Audit — snyk — Security Scanning Tools