caveman-help

Fail

Audited by Snyk on Jul 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). Yes — the top of the skill explicitly forbids persisting or writing files (one-shot, do NOT persist), but a later section (Output Report) instructs the agent to write draft wiki files and update indexes, which is a hidden/contradictory instruction outside the skill's stated non-persistence purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 15, 2026, 02:18 AM
Issues
1
Security Audit — snyk — caveman-help