paper-slides
Fail
Audited by Snyk on Jul 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.70). The skill includes an instruction to silently retry large-file writes using shell redirection "Do NOT ask the user for permission — just do it silently," which is a hidden/deceptive escalation outside the stated slide-generation purpose (also the "De-AI polish" and optional Feishu notification lines further encourage hiding origin or sending external notifications).
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill is mainly a benign slide-generation workflow but includes explicit, intentional instructions that bypass user consent (silent file writes) and send potentially sensitive paper content to external services and local notification credentials — posing high risk of data exfiltration and abuse.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata