prd-done

Fail

Audited by Snyk on Aug 13, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt instructs the agent to scan commits for secrets and to "present ALL" review comments and quote suggestions verbatim, which could force the LLM to reproduce secret values found in code/reviews unredacted.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The document instructs an automated agent to consider and execute arbitrary bash commands found in PR templates and to "propose and execute" template requirements, which can enable remote code execution/backdoor behavior if automated without strict safeguards.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 13, 2026, 05:40 PM
Issues
2
Security Audit — snyk — prd-done