spec-index

Fail

Audited by Snyk on Aug 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The skill contains explicit meta-level directives that tell the agent to ignore external "Claude-specific" mode-switch instructions and to self-authorize spawning subagents, which are instructions to override or bypass higher-level/environmental controls unrelated to the declared spec-indexing purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 24, 2026, 08:23 PM
Issues
1
Security Audit — snyk — spec-index