database-tactics

Fail

Audited by Snyk on Aug 12, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt includes explicit plaintext passwords and credential templates embedded in commands (e.g., netexec/impacket with sa/PASSWORD, common default passwords, and brute-force examples), which requires the LLM to output secret values verbatim and thus is insecure credential handling.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content is an explicit, actionable offensive guide for unauthorized database access, credential theft, RCE, and persistence (writing webshells/SSH keys/crontab), indicating intentional malicious intent and abuse potential.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能运行路径是在回答评测/用户提问时摄取“prompt”中的免费文本(例如 evals/evals.json 的 prompt)并据此生成数据库入侵步骤,因此存在被外部文本诱导的间接提示注入暴露。

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs unauthorized access, weak-password brute force, command execution and file writes (e.g., "写 Webshell / SSH 密钥 / Crontab") and guides OS privilege escalation on target systems, which directly encourages modifying machine state and system compromise.

Issues (4)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 12, 2026, 03:49 PM
Issues
4
Security Audit — snyk — database-tactics