ios-sync

Fail

Audited by Snyk on Jul 18, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). This skill includes a hidden/opaque instruction to embed a non-visible question_id marker (e.g. "gstack-qid:...") in rendered questions so hooks can auto-decide, which is a hidden/deceptive directive unrelated to the declared purpose of "resync the iOS debug bridge."

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 18, 2026, 11:46 AM
Issues
1
Security Audit — snyk — ios-sync