ai-full-code-review

Fail

Audited by Snyk on Aug 25, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The skill explicitly instructs the model to write review files directly into the user's local Obsidian vault and to delegate committing/pushing those files via an ai-commit helper, steering file-system and repo operations that could expose or move local data outside the immediate conversational context.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 08:54 PM
Issues
1
Security Audit — snyk — ai-full-code-review