cve-exploit-methodology
Fail
Audited by Snyk on Apr 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is high-risk: it is an actionable CVE-exploitation methodology that provides precise RCE payloads, reverse-shell commands, file-exfiltration techniques, post‑exploit/credential harvesting guidance, WAF/patch-bypass obfuscations, and instructions to fetch and run third‑party PoCs — all clearly facilitating deliberate system compromise and unauthorized access.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). SKILL.md (and references/cve-catalog.md) explicitly instructs the agent to fetch and read community Nuclei templates and external PoCs (e.g., reading ~/nuclei-templates, using search_vulndb/read_vuln, GitHub, ExploitDB, random blogs/Pastebin), which are untrusted third-party sources the agent must interpret and that can materially change its actions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata