offensive-osint

Fail

Audited by Snyk on Aug 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (critical risk: 1.00). This skill contains explicit, actionable offensive-reconnaissance and credential-exfiltration guidance — concrete probes, curl one-liners, secret regexes, live validators, and attack-path hints that clearly enable harmful intrusion and secret exfiltration.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). Outsider-authored free text exposure is indirect and occurs only when the operator actively targets and fetches external content (e.g., probing/collecting from a third-party site, GitHub code, Postman public workspaces, Stack Exchange bodies) rather than the runtime workflow passively ingesting queued/inbox/feed text.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 05:32 AM
Issues
2
Security Audit — snyk — offensive-osint