pentest-blackboard
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt directs agents to record original requests/responses and to upsert auth/cred-* facts and body/POC entries (including "凭据"/"完整秘密" handling), which can require embedding secrets verbatim into outputs.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The document contains explicit offensive guidance—automatic credential reuse ("spray"), active lateral scanning, and defense-evasion techniques (proxy chains, XFF, encoding) plus instructions for handling "loot"—which enable unauthorized access and exfiltration and can be abused as a backdoor/attack playbook.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata