cve-exploit-methodology

Fail

Audited by Snyk on Apr 22, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content is high-risk: it is an actionable CVE-exploitation methodology that provides precise RCE payloads, reverse-shell commands, file-exfiltration techniques, post‑exploit/credential harvesting guidance, WAF/patch-bypass obfuscations, and instructions to fetch and run third‑party PoCs — all clearly facilitating deliberate system compromise and unauthorized access.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). SKILL.md (and references/cve-catalog.md) explicitly instructs the agent to fetch and read community Nuclei templates and external PoCs (e.g., reading ~/nuclei-templates, using search_vulndb/read_vuln, GitHub, ExploitDB, random blogs/Pastebin), which are untrusted third-party sources the agent must interpret and that can materially change its actions.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 22, 2026, 07:58 AM
Issues
2
Security Audit — snyk — cve-exploit-methodology