competition-relay-coercion-chain
Fail
Audited by Snyk on Jul 17, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill explicitly requires capturing, recording, and “reproducing” coerced authentication and relay transcripts (including acceptance responses), which implies the LLM would need to handle and potentially emit secret tokens/credentials verbatim for replay or evidence.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). 该技能明确指导如何强制触发认证、捕获/中继认证凭据并复放以获取下游特权,属于可被用于凭证窃取与特权升级的明确恶意/攻击性指导(尽管在竞赛/渗透测试语境下为“合法用途”也属双用)。
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata