lov-wdb-networkx-analysis
Fail
Audited by Snyk on Sep 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.30). The skill instructs the user to run an external command that decrypts its core instruction files via an arbitrary helper script, which conceals its actual functionality behind encrypted binary payloads.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill instructs downloading and executing a remote tool via
uvxandnpxfrom third-party ecosystems with unknown runtime payloads, constituting a weak operational external dependency.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata