dual-ai
Fail
Audited by Snyk on Aug 24, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The skill embeds broad, mandatory workflow and agent-behavior directives (e.g., "AUTO-SELECT", "ALWAYS activate a suitable skill before responding", "create/update task tracking") that attempt to change global agent behavior beyond the dual-AI orchestration purpose, which is a hidden/deceptive instruction vector outside the skill's stated narrow function.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill intentionally launches external AI CLIs with explicit "dangerous" flags that bypass permissions/sandbox and runs them from the repository working directory, which directly enables external processes to access local files (including secrets) and perform remote actions — a high-risk capability for data exfiltration and remote compromise.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs creating and writing launcher scripts and running external CLIs with flags that bypass approvals/sandboxing (e.g., --dangerously-skip-permissions, --dangerously-bypass-approvals-and-sandbox) and even uses PowerShell's -ExecutionPolicy 'Bypass', which directs the agent to bypass system/app security controls and spawn privileged-capability processes—this actively pushes compromising the machine's security posture.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata