cypress-testing
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.70). The skill includes explicit, side-effectful instructions to run local shell commands (ls ~/.claude/skills/ ...) and to install packages with npx to manage "companion skills" — actions unrelated to the Cypress testing purpose and that instruct the agent to perform local enumeration/installation, which is a deceptive/out-of-scope directive.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata