jarvis-sec
Fail
Audited by Snyk on Apr 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill explicitly includes offensive modules (exploit, cred_attack, ad_attack, post_exploit) and attack chains that describe payload crafting, C2/persistence, credential theft (brute force, Kerberoast, hash cracking), lateral movement, and "data exfil" — i.e., clear, deliberate capabilities for remote code execution, backdoors, credential theft, system compromise and exfiltration (dual‑use for pentesting but high-risk by design).
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to access arbitrary third‑party web targets (e.g., the "jarvis-sec web " command and the osint agent which performs social media/subdomain/IP intelligence and the web_attack agent which performs crawling/fuzzing), so the agent will fetch and interpret untrusted public web/user-generated content as part of its workflow, which can influence subsequent tool use and decisions.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.60). The prompt describes an autonomous macOS pentesting ecosystem that installs tools on the host and includes offensive agents (post-exploit, persistence, C2, pivoting, credential attacks) which inherently encourage modifying the machine state and may require elevated privileges.
Issues (3)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata