hunt-cache-poison
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). The document provides detailed, actionable instructions and evasion techniques for conducting cache-poisoning attacks (including DoS, account takeover, and WAF/request-smuggling bypass), clearly enabling malicious exploitation.
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill includes example commands that require inserting an authenticated session cookie (session=YOUR_SESSION) and discusses session tokens being reflected/cached, which would require the LLM or user to embed a secret/session value verbatim into curl requests — an exfiltration risk.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata