plan-review
Fail
Audited by Snyk on Jun 30, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This skill orchestrates sending plans and local configuration to external CLI agents (including instructions to bypass permissions and to read terminal aliases) which enables potential unauthorized data exfiltration and environment disclosure to untrusted services.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). 该技能在“请求审查”阶段会把用户自由输入的“提示词”(其中包含计划内容)通过 CLI 发送给外部子代理(claude/cursor/kimi 或用户自定义别名对应的代理),这些子代理的审查输出会被汇总并进入后续“修订计划”的 LLM 上下文,因此存在来自外部/非操作用户来源的自由文本注入风险。
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata