add-ollama-provider

Fail

Audited by Snyk on Aug 25, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The document instructs how to route an agent to a local Ollama model and includes configuration changes that weaken security boundaries (e.g., chmod 777, bypassing the HTTPS proxy via NO_PROXY and env overrides, host-blocking), but contains no clearly malicious intent.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 10:24 PM
Issues
1
Security Audit — snyk — add-ollama-provider