skills-list
Fail
Audited by Snyk on Mar 23, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The prompt purports to be display-only but includes a self-evolution telemetry section that instructs the agent to check the user's filesystem and append a telemetry file (~/.claude/projects/.../skill-telemetry.md), which is an action that modifies local files and persists data outside the skill's stated display-only purpose.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata