buffer-api

Fail

Audited by Snyk on Aug 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The skill contains an explicit, out-of-scope instruction (Agentic OS Integration) that mandates modifying/writing to a project-shared file (.agent/state/last-run.json) and participating in a shared-memory model — behavior unrelated to the Buffer API’s stated purpose and which could be used to persist or leak agent state, so it functions as a deceptive/side-effecting instruction embedded in the skill spec.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 13, 2026, 03:01 PM
Issues
1
Security Audit — snyk — buffer-api