dast-automation

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The list is mixed — it contains legitimate documentation and known tool repos (e.g., OWASP, ProjectDiscovery, PortSwigger) but also multiple attacker-controlled domains, obfuscated/redirect-style URLs, cloud metadata endpoints, localhost/internal addresses and at least one direct release ZIP; those patterns (attacker domains, redirects, metadata endpoints and direct binary downloads) are commonly used in malware distribution, SSRF/exfiltration and exploitation, so the overall set should be treated as suspicious.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The repository contains multiple explicit offensive and post‑exploit patterns — webshells, remote code execution payloads/commands, instructions for exfiltrating secrets (DNS/HTTP/OOB/SSRF to cloud metadata), obfuscation techniques, and tooling to obtain shells — which are high‑risk backdoor and data‑exfiltration primitives usable for deliberate malicious abuse if run without strict authorization.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 17, 2026, 12:12 PM
Issues
2
Security Audit — snyk — dast-automation