agent-orchestration
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.30). The content instructs orchestrating code changes by delegating to a CLI worker (cursor-agent) and explicitly recommends/uses auto-approve flags (--force/--trust) and model-override avoidance, which weakens execution controls and could enable automated state-changing actions without interactive confirmation, but it is documentation for tooling rather than clearly malicious.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata