hunt-shadow-api

Fail

Audited by Snyk on Jul 22, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document is an offensive red-team/bug-hunting playbook that explicitly instructs discovery and exploitation of "zombie" API endpoints (including curl-based enumeration, auth bypass tests, rate-limit and validation regressions, and chaining to brute-force/injection attacks), and therefore enables deliberate unauthorized access and data exposure.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.72). High likelihood: the workflow explicitly fetches specs and indexes from outsider-controlled sources at runtime (public web content like Wayback Machine via web.archive.org/cdx and potentially arbitrary reachable /$path specs), and those retrieved JSON bodies can become LLM-readable context if the agent ingests them for diffing/analysis.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 22, 2026, 08:23 PM
Issues
2
Security Audit — snyk — hunt-shadow-api