oauth-helper

Fail

Audited by Snyk on Jun 14, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This skill intentionally automates OAuth authorizations using a pre-authenticated browser and an external Telegram channel (sending prompts, screenshots/QR codes, and soliciting 2FA codes), which creates a clear, intentional channel for data exfiltration and credential harvesting that can enable account takeover if the browser profile or Telegram endpoint is controlled by an attacker.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 14, 2026, 06:19 PM
Issues
2
Security Audit — snyk — oauth-helper