revyl-cli-auth-bypass-android

Fail

Audited by Snyk on May 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This skill implements an intentional "test-only" authentication bypass/backdoor via deep links and launch intent extras (REVYL_AUTH_BYPASS_*), which — if enabled in production or if the token/launch-vars are leaked/misconfigured — would allow unauthorized sign-in and navigation; no data-exfiltration, remote code execution, or obfuscation patterns are present, but the deliberate auth-bypass mechanism is a high-risk backdoor vector.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 15, 2026, 10:12 PM
Issues
1
Security Audit — snyk — revyl-cli-auth-bypass-android