hunt-write-gap

Fail

Audited by Snyk on Jul 31, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The presence of an external image hosted on "evil.com" (https://evil.com/pwned.png) used as an avatar URL is suspicious—external hosts can serve tracking, phishing content, or be swapped to deliver malicious payloads; api.target.com is just a placeholder API endpoint and not a download source.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document provides explicit, actionable instructions to exploit authenticated writeable endpoints for privilege escalation, financial manipulation, profile hijacking, and cross-user (IDOR) writes—clear guidance for malicious abuse.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly describes and demonstrates modifying account balances and creating financial "movements" via API calls (e.g., POST /movements with an "amount" field) and calls out "Balance injection" / "fake income" as a confirmed pattern. These are specific, financial-action endpoints (ledger/transaction creation and balance manipulation), not generic browser or API tooling, and therefore constitute direct financial execution capability.

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 31, 2026, 04:51 PM
Issues
3
Security Audit — snyk — hunt-write-gap