lov-wdb-networkx-analysis

Fail

Audited by Snyk on Sep 26, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The skill instructs the user to run an external command that decrypts its core instruction files via an arbitrary helper script, which conceals its actual functionality behind encrypted binary payloads.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill instructs downloading and executing a remote tool via uvx and npx from third-party ecosystems with unknown runtime payloads, constituting a weak operational external dependency.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 26, 2026, 10:16 AM
Issues
2
Security Audit — snyk — lov-wdb-networkx-analysis