hunt-file-upload
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). The document explicitly provides step-by-step attack techniques, payloads, and chaining methods to bypass file-upload protections and achieve RCE, XSS, SSRF, and data exfiltration.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow (“hunt-file-upload”) ingests outsider-authored free text only in the form of uploader-provided filenames/content into the target’s upload/parse/serve pipeline (e.g., avatar/attachment/import endpoints) and then requests the resulting URL to validate RCE/XSS/SSRF/XXE—i.e., the attacker can submit arbitrary payload text that the agent-driven workflow reads and tests.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata