ssti-detect
Fail
Audited by Snyk on Mar 25, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). Although the skill claims "仅做检测和引擎判断" (detection-only), it explicitly advises exploitation steps—e.g. "优先尝试
{{flag}}直接访问上下文变量" and points to an exploitation skill—i.e. instructions to access/exfiltrate secrets outside the stated scope.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata