agent-feedback-artifact
Fail
Audited by Snyk on Jun 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill intentionally ships a configurable webhook-based delivery that posts artifact/context/comments (including selected text, element snapshots, URLs, and full comment payloads) to an external URL, and exposes unauthenticated local HTTP endpoints (queue, dispatch, status, message delete) plus a test auto-runner that can modify artifact files — together these are deliberate data-exfiltration and remote-control primitives that are safe only when the webhook and server are trusted and access is strictly local.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata