counsel
Fail
Audited by Snyk on Jul 30, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content includes an explicit command flag that instructs bypassing approvals and sandboxing, which is a deliberate instruction to circumvent security controls and enables high-risk remote/code-execution behavior.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In the Codex/GitHub Copilot CLI chair workflow, the only outsider-authored free text the seats ingest at runtime is the user-provided “{proposal path}” and “{source paths}” contents (files chosen/uploaded by the user), and the runtime does not appear to read arbitrary external/third-party text feeds or queues.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata