qa-plan

Fail

Audited by Snyk on Aug 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.60). The skill instructs the agent to "Silently append" a session-state entry (write a file without user notification or approval), which is a hidden side-effect not disclosed in the main outputs and contradicts the "Never write the plan without asking" rule—this is a deceptive instruction outside the skill's stated, user-approved behavior.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 24, 2026, 04:18 PM
Issues
1
Security Audit — snyk — qa-plan