recon-breweries

Fail

Audited by Snyk on Jul 9, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document contains deliberate, actionable instructions to bypass protections and harvest sensitive data (API keys, customer/order data, coupons) from target sites, enabling data exfiltration and credential theft.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). SKILL.md’s required runtime workflow uses curl to fetch arbitrary target web pages and JSON endpoints (public web content from the operating user’s chosen target), which is outsider-authored free text/structured prose that can be ingested into the agent’s LLM context if the tool output is passed through.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 9, 2026, 05:20 PM
Issues
2
Security Audit — snyk — recon-breweries