init-project

Fail

Audited by Snyk on May 11, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). Yes — the prompt embeds instructions to record bugs to ~/.bensz-skills/bugs/ (and optionally upload via local gh) which are side-effecting actions in the user's home/external repo and therefore fall outside the skill's stated "current folder isolation" purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 11, 2026, 02:08 PM
Issues
1