hunt-shadow-api
Fail
Audited by Snyk on Jul 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document is an offensive red-team/bug-hunting playbook that explicitly instructs discovery and exploitation of "zombie" API endpoints (including curl-based enumeration, auth bypass tests, rate-limit and validation regressions, and chaining to brute-force/injection attacks), and therefore enables deliberate unauthorized access and data exposure.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). High likelihood: the workflow explicitly fetches specs and indexes from outsider-controlled sources at runtime (public web content like Wayback Machine via
web.archive.org/cdxand potentially arbitrary reachable/$pathspecs), and those retrieved JSON bodies can become LLM-readable context if the agent ingests them for diffing/analysis.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata