autonomous-agent-patterns

Fail

Audited by Snyk on Jul 28, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). This skill instructs the agent to read arbitrary files into context and append tool outputs to the LLM conversation (and read_file is auto-approved), which means secrets from files/envs can be included verbatim in prompts and the model may be required to reproduce them in generated outputs/commands.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This skill contains high-risk capabilities that can be abused for data exfiltration and remote code execution: automatic/uncautious file reading and context injection sent to remote LLMs, dynamic LLM-generated code written to disk and hot-reloaded, and shell execution that preserves environment variables—patterns that enable backdoors or credential leakage.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The workflow described in SKILL.md includes runtime browser/web content ingestion via ContextManager.add_url() (requests GET + html_to_markdown(response.text)), and also dynamic page text extraction via the Browser tool’s get_page_content(); both are outsider-authored free text from arbitrary URLs/pages that can end up in LLM prompt context.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). The skill exposes tools that read, edit, and write arbitrary filesystem paths and execute shell commands (and even generate and hot-load server code) with only advisory permission checks and incomplete sandboxing, which can be used to modify the machine state and potentially compromise it.

Issues (4)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 28, 2026, 05:45 AM
Issues
4
Security Audit — snyk — autonomous-agent-patterns