business-logic-vulnerabilities
Fail
Audited by Snyk on Jul 21, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill explicitly instructs testers to capture and copy authentication cookies/tokens and replay them into requests (cookie-replacement), which requires handling and embedding secret session values verbatim — a high exfiltration risk.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). Several entries point to known attack tooling and a direct zip-bomb download (zip file), which are high-risk sources for delivering malicious payloads or causing resource exhaustion.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The files are an offensive business-logic attack playbook with explicit, actionable instructions for data exfiltration, account takeover, remote command execution, webshell uploads, payment fraud, SMS-bombing and DoS—content that can be directly abused for malicious activity.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata