jarvis-sec

Fail

Audited by Snyk on Apr 18, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill explicitly includes offensive modules (exploit, cred_attack, ad_attack, post_exploit) and attack chains that describe payload crafting, C2/persistence, credential theft (brute force, Kerberoast, hash cracking), lateral movement, and "data exfil" — i.e., clear, deliberate capabilities for remote code execution, backdoors, credential theft, system compromise and exfiltration (dual‑use for pentesting but high-risk by design).

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to access arbitrary third‑party web targets (e.g., the "jarvis-sec web " command and the osint agent which performs social media/subdomain/IP intelligence and the web_attack agent which performs crawling/fuzzing), so the agent will fetch and interpret untrusted public web/user-generated content as part of its workflow, which can influence subsequent tool use and decisions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.60). The prompt describes an autonomous macOS pentesting ecosystem that installs tools on the host and includes offensive agents (post-exploit, persistence, C2, pivoting, credential attacks) which inherently encourage modifying the machine state and may require elevated privileges.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 18, 2026, 12:08 PM
Issues
3
Security Audit — snyk — jarvis-sec