offensive-osint
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). This skill contains explicit, actionable offensive-reconnaissance and credential-exfiltration guidance — concrete probes, curl one-liners, secret regexes, live validators, and attack-path hints that clearly enable harmful intrusion and secret exfiltration.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Outsider-authored free text exposure is indirect and occurs only when the operator actively targets and fetches external content (e.g., probing/collecting from a third-party site, GitHub code, Postman public workspaces, Stack Exchange bodies) rather than the runtime workflow passively ingesting queued/inbox/feed text.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata