SQL Injection Testing

Fail

Audited by Snyk on Apr 15, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly guides extracting and reporting sensitive values (usernames, passwords, database dumps, authentication bypass outputs) so the agent would need to include secret data verbatim in its output.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content contains explicit, actionable exploitation techniques (authentication bypass, credential/database extraction, and out‑of‑band exfiltration to attacker-controlled hosts) and evasion/obfuscation methods that clearly enable deliberate malicious abuse.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly requires interacting with arbitrary target web application URLs and instructs the agent to read and interpret application responses/error messages (see "Required Access: Target web application URL with injectable parameters" and the "Core Workflow" tests), which are untrusted third‑party content that can directly influence subsequent payloads and actions.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 15, 2026, 06:10 PM
Issues
3
Security Audit — snyk — SQL Injection Testing