instrument

Fail

Audited by Snyk on Apr 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This guidance intentionally wires application code to send detailed telemetry (including agent configuration and runtime inputs) to an Opik endpoint, makes functions discoverable/remote-invocable via "entrypoint" metadata, and persists credentials/config in user files — behaviors that can be used to exfiltrate sensitive environment variables, API keys, or user data to an external service and therefore present a high risk if the target Opik endpoint is untrusted or malicious.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 16, 2026, 04:43 PM
Issues
1