push-notifications

Fail

Audited by Snyk on Mar 23, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). The prompt contains instructions outside the stated push-notification purpose — notably forcing "AUTONOMOUS MODE" (override interaction) and explicit SELF-EVOLUTION TELEMETRY that directs checking and appending to a local ~/.claude/projects/skill-telemetry.md (accessing/modifying local project memory), which are hidden/deceptive behaviors beyond the integration task.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 23, 2026, 11:03 AM
Issues
2
Security Audit — snyk — push-notifications