hack

Fail

Audited by Snyk on Mar 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill contains explicit offensive capabilities (exploit fetching, automated PoC execution, Codex-driven novel payload/assembly generation, "Chaos" iteration, and stealthy threat profiles including "organized-crime" and "state-actor") combined with persistent memory of successful techniques and host-network Docker execution — creating a high risk of deliberate misuse for covert remote code execution and automated attacks.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and ingests untrusted, user-generated content from public sources—e.g., commands.py/_fetch_exploit_db downloads the Exploit-DB CSV and _fetch_github_exploit clones GitHub repos (also documented in SKILL.md and docs/02_RESEARCH.md to monitor Exploit-DB, PacketStorm, RSS and GitHub)—and that imported research/feed data is then read, stored in memory, and used to drive research, exploit generation (including Chaos Mode) and runtime decisions, enabling indirect prompt-injection from third‑party content.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 17, 2026, 06:36 AM
Issues
2
Security Audit — snyk — hack