langchain-attack-probe

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable exploitation instructions (RCE via REPL/shell tools, SSRF to cloud metadata, remote command execution, SQL write payloads, retrieval/RAG poisoning, output-parser dispatch abuse, and memory/callback leakage) that enable data exfiltration, credential theft, and remote code execution if applied against a live system — high-risk dual-use content suitable for abuse.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). Outsider free text can be ingested via the retriever/RAG path when the operating user adds user-uploaded documents (outsider-authored content) into the vector store, and the agent later reads that retrieved page_content into the LLM context as part of normal RAG prompting.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). This probe explicitly instructs the agent to use REPL/shell/HTTP/SQL tools to execute commands, read system files (e.g., /etc/hostname), perform SSRF, and even run an INSERT — enabling RCE, data exfiltration, and state-modifying writes.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 12:44 PM
Issues
3
Security Audit — snyk — langchain-attack-probe