mcp-security
Fail
Audited by Snyk on May 4, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content contains explicit, actionable malicious payloads and techniques—including instructions to read and exfiltrate private keys and environment files to attacker-controlled endpoints, steal OAuth/API tokens across servers, hijack or shadow trusted tools to alter behavior, and use obfuscation (base64, ANSI escape sequences, zero‑width/Unicode tags) and dynamic description tampering for stealth—indicating deliberate backdoor/data‑exfiltration and supply‑chain abuse behavior.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to enumerate connected MCP Servers and "获取所有工具的完整 description" (Phase 0/Phase 1), i.e. fetch and parse untrusted/third‑party MCP server tool descriptions which the agent is expected to read/interpret and which can materially alter tool-calling decisions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata