uxaudit
Fail
Audited by Snyk on Jul 9, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The TomeVault links (tomevault.io and tomevault.io/install) point to an unfamiliar third‑party site offering an "installer/relay" for distributing skill packages — a common vector for delivering executables — while the GitHub URLs are standard public repo pages and are not suspicious by themselves.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Outsider-authored free text can enter the LLM context via the runtime “Scout” subagent (Phase 01 Step 4) which uses WebSearch/WebFetch and reads the project’s own files to synthesize
project-context.json, and those fetched pages / discovered text are not authored by the operating user.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata