cross-review

Fail

Audited by Snyk on May 11, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). The prompt repeatedly states the skill is report-only and will not apply automatic fixes, but section 5 instructs the agent to autonomously apply fixes for "warning" findings without user confirmation, a contradictory instruction that changes agent behavior beyond the skill's stated purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 11, 2026, 08:21 AM
Issues
1
Security Audit — snyk — cross-review