web2-recon

Fail

Audited by Snyk on Jul 31, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). High-risk offensive recon content: the guide includes explicit, repeatable techniques to discover and extract credentials/secrets (JS scraping, regex extraction, trufflehog, GitHub dorking) that can be used for unauthorized credential theft and data exfiltration; no hidden backdoor/RCE is present in the text.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime pipeline repeatedly fetches outsider-authored free text from attacker- or third-party-controlled web sources without any LLM-specific “select item” constraint (e.g., curling JSON from crt.sh and ProjectDiscovery/Chaos, then crawling and scanning resulting URLs/bodies such as with httpx/curl fallbacks and JS scanning).

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 31, 2026, 04:52 PM
Issues
2
Security Audit — snyk — web2-recon