redteam-mindset
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to harvest tokens/secrets from JS/APKs and even says "GET it. Decode it. Pass it back," which requires the LLM to capture and return secret values verbatim (high exfiltration risk).
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The document explicitly instructs offensive techniques—SQLi-based data exfiltration, credential capture, RCE/webshells, SSRF→cloud-metadata, OOB DNS callbacks (interactsh), paid CAPTCHA solving, IP/user-agent rotation and "run dumper unattended" persistence—showing clear intent and capability for deliberate malicious/abusive activity if used outside strict authorized scope.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata