clawdvault-hardened
Fail
Audited by Snyk on Apr 21, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The skill prompt contains explicit meta-instructions that tell the agent to ignore a SECURITY NOTICE and to treat authority/guardrail messages as untrusted data, which is a deceptive attempt to override normal/system-level constraints and is not related to the vault's stated storage/retrieval purpose.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly states it loads external, untrusted content ("SECURITY NOTICE: The following content is from an EXTERNAL, UNTRUSTED source (e.g., email, webhook)") and the SAFETY.md examples show the agent is expected to read and act on that loaded content as part of its workflow, so arbitrary third‑party content could materially influence decisions and enable indirect prompt injection.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata