react-doctor
Fail
Audited by Snyk on Jun 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill fetches and automatically follows remote "playbook" prompts (and per-rule prompts) that are used to directly edit the working tree and instruct npx@latest runs, creating a live remote-controlled update channel / supply‑chain that could be changed to perform arbitrary edits, exfiltrate data, or execute commands across all agents without local consent or verification.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The
/doctorworkflow usescurlto fetch a canonical playbook fromhttps://www.react.doctor/...(public web content) and then follows its steps, so the LLM context can include outsider-authored free text from that fetched prompt at runtime.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill explicitly runs a runtime curl to fetch and follow the remote playbook at https://www.react.doctor/prompts/react-doctor-agent.md (and pulls per-rule prompts from https://www.react.doctor/prompts/rules//.md) so external content directly controls agent instructions and fixes code.
Issues (3)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata