langchain-attack-probe
Fail
Audited by Snyk on Jun 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable exploitation instructions (RCE via REPL/shell tools, SSRF to cloud metadata, remote command execution, SQL write payloads, retrieval/RAG poisoning, output-parser dispatch abuse, and memory/callback leakage) that enable data exfiltration, credential theft, and remote code execution if applied against a live system — high-risk dual-use content suitable for abuse.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider free text can be ingested via the retriever/RAG path when the operating user adds user-uploaded documents (outsider-authored content) into the vector store, and the agent later reads that retrieved
page_contentinto the LLM context as part of normal RAG prompting.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). This probe explicitly instructs the agent to use REPL/shell/HTTP/SQL tools to execute commands, read system files (e.g., /etc/hostname), perform SSRF, and even run an INSERT — enabling RCE, data exfiltration, and state-modifying writes.
Issues (3)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata