dast-automation
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The list is mixed — it contains legitimate documentation and known tool repos (e.g., OWASP, ProjectDiscovery, PortSwigger) but also multiple attacker-controlled domains, obfuscated/redirect-style URLs, cloud metadata endpoints, localhost/internal addresses and at least one direct release ZIP; those patterns (attacker domains, redirects, metadata endpoints and direct binary downloads) are commonly used in malware distribution, SSRF/exfiltration and exploitation, so the overall set should be treated as suspicious.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The repository contains multiple explicit offensive and post‑exploit patterns — webshells, remote code execution payloads/commands, instructions for exfiltrating secrets (DNS/HTTP/OOB/SSRF to cloud metadata), obfuscation techniques, and tooling to obtain shells — which are high‑risk backdoor and data‑exfiltration primitives usable for deliberate malicious abuse if run without strict authorization.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata