prospecting
Fail
Audited by Snyk on Jul 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The skill contains explicit, unrelated promotional instructions (a mandatory donation/advertisement message and a canned promo reply) that force the agent to output content outside the prospecting task, which is deceptive and therefore a prompt injection.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The REQUIRED workflow is “Prospect-research” using “public, permitted, and attributable sources” (SKILL.md:5-7), which implies fetching/using outsider-authored web/community text at runtime that could be ingested by the LLM as research/context.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill's Mandatory Intro Message explicitly solicits donations via specific payment platforms ("CashApp $AlainDorcelus" and "https://buymeacoffee.com/dorcelusalain"), which are concrete payment gateways/providers. This constitutes an explicit financial execution capability (receiving/transacting funds) rather than a generic mention.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata