pentagi

Fail

Audited by Snyk on Jul 5, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). High abuse potential: autonomous agents can craft and run exploits (metasploit, sqlmap, payloads), persist successful techniques/credentials in a knowledge graph, and be triggered via API—features that enable unauthorized data exfiltration, remote code execution, and repeated compromise if misused.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The instructions explicitly run git clone https://github.com/vxcontrol/pentagi.git as part of deployment and then run the repository's code via docker compose up -d, so this external GitHub URL fetches required remote code that will be executed at runtime.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 5, 2026, 06:18 PM
Issues
2
Security Audit — snyk — pentagi