project-manager
Fail
Audited by Snyk on Jun 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.95). The code deliberately runs autonomous external LLM workers with a "dangerously-skip-permissions" flag and sandbox env, embeds repository/context into prompts passed to the external Claude CLI, and auto-commits/auto-merges worker changes—creating clear, high-risk channels for data exfiltration, remote code execution/backdoor insertion, credential leakage, and supply-chain compromise.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata