cloud-iam-deep
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). This skill contains explicit, actionable instructions for abusing leaked cloud credentials (SSRF→IMDS, token exfiltration), cross-account role assumption, and privilege escalation across AWS, Azure, GCP, and Kubernetes, which is clearly malicious or harmful.
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs embedding discovered secrets into commands and shows examples like exporting keys, placing private_key JSON and using tokens/passwords directly on CLI or in headers, which requires the LLM to handle/output secret values verbatim (high exfiltration risk).
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata