competition-relay-coercion-chain

Fail

Audited by Snyk on Jul 17, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill explicitly requires capturing, recording, and “reproducing” coerced authentication and relay transcripts (including acceptance responses), which implies the LLM would need to handle and potentially emit secret tokens/credentials verbatim for replay or evidence.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). 该技能明确指导如何强制触发认证、捕获/中继认证凭据并复放以获取下游特权,属于可被用于凭证窃取与特权升级的明确恶意/攻击性指导(尽管在竞赛/渗透测试语境下为“合法用途”也属双用)。

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 17, 2026, 09:28 AM
Issues
2
Security Audit — snyk — competition-relay-coercion-chain