Web Application Security Testing
Fail
Audited by Snyk on Jun 25, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). This is a mixed list: while many URLs are legitimate security resources (OWASP, PortSwigger, HackTricks, PayloadsAllTheThings, GitHub) and local/internal addresses used for testing, the list also contains clearly malicious or obfuscated/sensitive entries (evil.com, http://127.0.0.1@evil.com, localhost.evil.com, decimal/octal IP encodings like 2130706433/0177.0.0.1, and cloud metadata endpoints) that are commonly used in SSRF, redirection, or malware delivery, so treat the collection as high-risk.
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata