web-app-logic
Fail
Audited by Snyk on May 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill content contains numerous explicit exploitation techniques and automated scripts (RCE/web shells, data exfiltration via cache deception and request smuggling, credential/backup harvesting, automated fraud loops like gift-card/price manipulation, race-condition single-packet attacks, and tooling to mass-exploit targets) which can be directly abused for theft, compromise, persistence and large-scale malicious attacks.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's documentation and workflow files (e.g., access-control-quickstart.md and access-control-cheat-sheet.md) contain explicit, required instructions and scripts to fetch and parse arbitrary public web content (curl/requests against http://target.com, checking /robots.txt, reading JS bundles, blog posts, etc.), and those untrusted third‑party pages are expected to be read and used to drive subsequent testing actions—meeting the criteria for indirect prompt injection risk.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata