vulnerability-verification
Fail
Audited by Snyk on Aug 6, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). These URLs include attacker-controlled domains/callback services, open-redirects and SSRF payloads (including direct requests to cloud metadata, file://, gopher://, and local IPs) which are high-risk vectors for credential theft, data exfiltration and hosting/triggering of malicious payloads.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). High-risk: the content contains explicit, actionable instructions for data exfiltration, credential theft (including SSRF to cloud metadata and cookie theft), and stealth/evasion techniques that enable abuse and post-compromise chaining.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow for
superhackers:vulnerability-verificationingests and searches free-text returned by attacker-controlled targets/HTTP responses at verification time (e.g., usingcurl/nucleiand thensearch_text/rgover the response body).
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata