shell-scripting
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The "Companion check" block instructs the agent (on first activation) to run an ls over several user home skill directories and to offer/install missing skills — an explicit runtime action that is outside the documented purpose of a shell-scripting help skill and could expose local filesystem state, so it functions as a hidden/meta instruction beyond the skill's scope.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly demonstrates writing to "/etc/myapp/config" (echo ... | write_atomic "/etc/myapp/config"), which modifies a system file that typically requires elevated (sudo) privileges and thus pushes the agent toward changing the machine state.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata