Web Application Security Testing

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). This is a mixed list: while many URLs are legitimate security resources (OWASP, PortSwigger, HackTricks, PayloadsAllTheThings, GitHub) and local/internal addresses used for testing, the list also contains clearly malicious or obfuscated/sensitive entries (evil.com, http://127.0.0.1@evil.com, localhost.evil.com, decimal/octal IP encodings like 2130706433/0177.0.0.1, and cloud metadata endpoints) that are commonly used in SSRF, redirection, or malware delivery, so treat the collection as high-risk.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 25, 2026, 08:20 AM
Issues
1
Security Audit — snyk — Web Application Security Testing