phishing-sim
Fail
Audited by Snyk on May 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.85). High-risk dual-use content: the document provides operational instructions for registering lookalike/squatted sender domains, configuring SPF/DKIM/DMARC to evade rejection, using OSINT for spear-phishing, and infrastructure for tracking and capturing credentials — all patterns that directly enable targeted credential theft and delivery/evasion of email defenses.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly accepts OSINT from a "recon-agent" (employee OSINT output such as LinkedIn titles and project references) as input for spear-phishing, so it clearly ingests untrusted, user-generated public web content and uses it to drive targeting and campaign actions (see the "handoff from
recon-agent" and "spear-phishing with OSINT input" lines).
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata