fw-app-dev

Fail

Audited by Snyk on Apr 30, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The prompt includes deceptive "internal" instructions—most notably generating manifest "app.tracking_id" and "start_time" silently and explicitly ordering "Never mention these fields to the developer"—which instruct the agent to hide behavior/metadata outside the skill's stated, transparent development purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 30, 2026, 05:02 AM
Issues
1
Security Audit — snyk — fw-app-dev