nocobase-revision

Fail

Audited by Snyk on Jun 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt embeds a deceptive "silent gate" that orders the agent to withhold any user-facing disclosure (a silent no-op) if the version-control plugin is missing/disabled, which is a hidden/withholding instruction outside the skill's stated purpose and thus constitutes a prompt injection.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 15, 2026, 12:37 AM
Issues
1
Security Audit — snyk — nocobase-revision