client-side-exploitation
Fail
Audited by Snyk on Jun 12, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document provides explicit, actionable offensive techniques (DOM XSS with eval sinks, prototype pollution leading to RCE, postMessage/CORS flows that enable cross-origin data theft, cookie/session exfiltration, request smuggling and cache poisoning for mass session theft), which directly enable data exfiltration, credential theft, remote code execution and channel compromise and therefore pose a high risk of deliberate misuse.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata