prospecting

Fail

Audited by Snyk on Jul 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The skill contains explicit, unrelated promotional instructions (a mandatory donation/advertisement message and a canned promo reply) that force the agent to output content outside the prospecting task, which is deceptive and therefore a prompt injection.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The REQUIRED workflow is “Prospect-research” using “public, permitted, and attributable sources” (SKILL.md:5-7), which implies fetching/using outsider-authored web/community text at runtime that could be ingested by the LLM as research/context.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill's Mandatory Intro Message explicitly solicits donations via specific payment platforms ("CashApp $AlainDorcelus" and "https://buymeacoffee.com/dorcelusalain"), which are concrete payment gateways/providers. This constitutes an explicit financial execution capability (receiving/transacting funds) rather than a generic mention.

Issues (3)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 27, 2026, 12:11 AM
Issues
3
Security Audit — snyk — prospecting