create-context

Fail

Audited by Snyk on Mar 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill intentionally gathers sensitive local data (environment variables including API keys, session transcripts, memory files, inbox messages, filesystem paths, running processes and code snippets) and contains a memory_integration hook that will transmit collected summaries/decisions/lessons/issues to an external MemoryClient (if configured), which creates a clear risk of data exfiltration and credential leakage — no obfuscation or reverse shell is present, but the data-collection + optional remote-learn behavior functions as a potential backdoor/exfiltration vector if the memory backend is external or misused.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 17, 2026, 06:35 AM
Issues
1
Security Audit — snyk — create-context