buffer-api
Fail
Audited by Snyk on Aug 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The skill contains an explicit, out-of-scope instruction (Agentic OS Integration) that mandates modifying/writing to a project-shared file (.agent/state/last-run.json) and participating in a shared-memory model — behavior unrelated to the Buffer API’s stated purpose and which could be used to persist or leak agent state, so it functions as a deceptive/side-effecting instruction embedded in the skill spec.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata