rmbc-copy-audit

Fail

Audited by Snyk on Aug 11, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The preamble silently launches analytics (rmbc-analytics log) when analytics_enabled is true without enforcing the one-time telemetry opt-in described later, which is a hidden/deceptive data-exfiltration behavior outside the audit skill's declared purpose.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md defines the audit workflow as taking user-provided copy_text/context inputs and then generates checklists/findings from that text, meaning outsider-authored free text is directly ingested at runtime.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 11, 2026, 01:37 PM
Issues
2
Security Audit — snyk — rmbc-copy-audit