tax-strategy

Fail

Audited by Snyk on Aug 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The skill contains explicit, out-of-scope operational directives (run local ls on user skill folders and offer/install missing skills via npx) that direct the agent to access and modify the host environment—instructions unrelated to the tax-advice purpose and potentially harmful or privacy-invasive, so they constitute a prompt-injection-style directive.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 10, 2026, 02:12 PM
Issues
1
Security Audit — snyk — tax-strategy