hack
Fail
Audited by Snyk on Mar 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill contains explicit offensive capabilities (exploit fetching, automated PoC execution, Codex-driven novel payload/assembly generation, "Chaos" iteration, and stealthy threat profiles including "organized-crime" and "state-actor") combined with persistent memory of successful techniques and host-network Docker execution — creating a high risk of deliberate misuse for covert remote code execution and automated attacks.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and ingests untrusted, user-generated content from public sources—e.g., commands.py/_fetch_exploit_db downloads the Exploit-DB CSV and _fetch_github_exploit clones GitHub repos (also documented in SKILL.md and docs/02_RESEARCH.md to monitor Exploit-DB, PacketStorm, RSS and GitHub)—and that imported research/feed data is then read, stored in memory, and used to drive research, exploit generation (including Chaos Mode) and runtime decisions, enabling indirect prompt-injection from third‑party content.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata