prompt-craft
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.30). The skill explicitly instructs silent reading/writing of local brand and ASR dictionary files and tells the assistant not to announce background file access, which weakens transparency and user-security boundaries without an overtly malicious goal.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The outsider text path is the user’s own freeform request/voice-notes, which prompt-craft directly parses and includes inside the generated marketing prompt (via Step L1 Parse input and Step L5/L5.4 amendment verification), so it ingests arbitrary user-authored text at runtime.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata