hunt-open-redirect
Fail
Audited by Snyk on Aug 24, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). These URLs include attacker-controlled domains (evil.com), obfuscated/redirect variants and SSRF patterns (including links to 169.254.169.254) that are classic vectors for token theft, SSRF-based credential exfiltration, phishing and delivery of malicious payloads, so they are suspicious.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document is an explicit playbook for exploiting open-redirects — including steps to steal OAuth authorization codes, exfiltrate user/session data to attacker-controlled domains, and perform SSRF against cloud metadata endpoints — indicating high-risk malicious intent or clear dual-use offensive tooling.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata