direct-response-lander-copy
Fail
Audited by Snyk on Apr 14, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The content contains explicit, repeatable instructions for deceptive social-engineering and fraudulent marketing practices (fake bylines/publication names, guidance to fabricate or reuse testimonials, advice to present advertorials as neutral journalism and to cite/implicate research without verification, plus prompts to harvest verbatim user quotes) which pose a high risk of enabling impersonation, consumer fraud, privacy abuse, and misinformation—there are no signs of technical malware/backdoors but the behavioral abuse risk is high.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md Phase 1 "Avatar Deep Dive" explicitly instructs searching and scraping user-generated public sites (Reddit, forums, Amazon reviews, Quora) and to collect verbatim quotes for use in the copy, which requires ingesting untrusted third‑party content that can materially influence the agent's outputs.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata