vapt
Fail
Audited by Snyk on Jul 2, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt contains multiple examples that embed credentials and tokens directly into commands (e.g., SMB/Metasploit passwords, wpscan API token, nxc -p 'P@ss'), and instructs workflows that would require inserting real secret values verbatim into generated commands or scripts, creating an exfiltration risk.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). Yes — the list contains multiple high-risk indicators (exposed backup archives like backup.zip/www.tar.gz, DB dumps and .env/.git files, unknown GitHub repo NetExec, raw installer scripts, and endpoints that allow SSRF/file fetch) which could expose sensitive data or be abused to host or distribute malware.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content is an explicit offensive VAPT toolkit and playbook containing ready-to-run exploit chains, reverse-shell/payload generators, credential-harvesting and data-exfiltration commands, and Metasploit/meterpreter post‑exploitation steps — all high-risk capabilities that can be directly used to compromise systems or install backdoors if misused.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata