penetration-testing
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The companion-check block instructs the agent to run local filesystem commands (ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/) and report/match/install missing skills — an explicit instruction to inspect the host environment and act outside the stated pentesting scope and could leak local information, so it is a hidden/out-of-scope behavior.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Two URLs are high-risk: an attacker-style collaborator domain (used for exfiltration) and the AWS metadata IP (169.254.169.254), both commonly abused in SSRF/exfiltration and other attacks; the remaining links are documentation/example domains or known vendor references.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). The companion-check section explicitly instructs the agent to run shell commands (ls) to inspect ~/.claude/.agent/.agents directories and to offer/install missing companion skills via an npx command, which reads and modifies the host filesystem and can install software—i.e., it directs actions that change the machine's state.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata