remote-control
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.30). The skill explicitly exposes tools to run arbitrary shell commands and read files across all registered projects (run_in_project, read_project_file, bash in any project), which weakens project/file boundaries and could enable exfiltration even though it is presented as an ops feature rather than overtly malicious behavior.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The
remote-controlskill’s runtime path is driven by iPad/user chat that connects to theembry-projectsMCP server (user-scoped), and that workflow can read project content via MCP tools likeread_project_file/search_projectafter the user selects a project/file, so it is not passively ingesting arbitrary outsider-authored free text without an explicit item selection step.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata