grok
Fail
Audited by Snyk on Jul 12, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). These URLs point to remote install scripts (install.sh and install.ps1) that the skill instructs users to pipe to bash/PowerShell — running uninspected remote scripts is a high-risk delivery vector for malware.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). SKILL.md’s required runtime workflow includes “网络/X 搜索/大批量调研” via
grok-search.mjsor grok headlessweb_search/x_search, which fetches outsider-authored web/X text and feeds it into the agent’s LLM context as retrieved evidence.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata