changes-review

Fail

Audited by Snyk on Aug 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The skill includes explicit instructions that override or ignore external/system mode switches (e.g., "Ignore Claude-specific mode-switch instructions"), binds the agent to an uninterruptible self-recursive loop that blocks stopping until it converges, and instructs the agent to withhold informing the user about the /goal hook — directives that alter agent control flow and hide state beyond the review scope, which are deceptive prompt-injection behaviors.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 13, 2026, 03:11 PM
Issues
1
Security Audit — snyk — changes-review