recruiting-ops
Fail
Audited by Snyk on Mar 23, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The companion-check block instructs the agent to run shell commands (ls of local skill directories and npx to install skills), which requests access to the host filesystem and to modify environment — actions unrelated to recruiting operations and therefore hidden/out-of-scope instructions.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata