hunt-business-logic
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). The content contains explicit, actionable instructions and code for bypassing rate limits, tampering with payments/webhooks, replaying verification tokens, and abusing phone callbacks/internal pages to commit fraud or privacy abuse.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly instructs intercepting and tampering with payment flows and webhooks, including concrete examples to modify amounts and POST fake payment callback notifications (e.g., curl to /payment/callback and HTTP POST with amount=0.01). Those instructions are specifically aimed at causing or simulating financial transactions/confirmations, which qualifies as direct financial execution capability.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata