web-app-logic

Fail

Audited by Snyk on May 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill content contains numerous explicit exploitation techniques and automated scripts (RCE/web shells, data exfiltration via cache deception and request smuggling, credential/backup harvesting, automated fraud loops like gift-card/price manipulation, race-condition single-packet attacks, and tooling to mass-exploit targets) which can be directly abused for theft, compromise, persistence and large-scale malicious attacks.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's documentation and workflow files (e.g., access-control-quickstart.md and access-control-cheat-sheet.md) contain explicit, required instructions and scripts to fetch and parse arbitrary public web content (curl/requests against http://target.com, checking /robots.txt, reading JS bundles, blog posts, etc.), and those untrusted third‑party pages are expected to be read and used to drive subsequent testing actions—meeting the criteria for indirect prompt injection risk.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 13, 2026, 10:30 PM
Issues
2
Security Audit — snyk — web-app-logic