oauth-helper
Fail
Audited by Snyk on Jun 14, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This skill intentionally automates OAuth authorizations using a pre-authenticated browser and an external Telegram channel (sending prompts, screenshots/QR codes, and soliciting 2FA codes), which creates a clear, intentional channel for data exfiltration and credential harvesting that can enable account takeover if the browser profile or Telegram endpoint is controlled by an attacker.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata