competition-android-hooking

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs capturing plaintext inputs, tokens, signatures, headers, and replaying accepted requests, which requires the LLM/agent to handle and output secret values verbatim.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). 该技能文档明确指导绕过 SSL 钉扎与环境检查、挂钩请求签名/加密边界以记录明文、捕获令牌/密钥并重放请求、修改并重签 APK 等步骤,明显支持凭证窃取、数据外泄和可被滥用的后门/供应链攻击路径。

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 20, 2026, 03:16 AM
Issues
2
Security Audit — snyk — competition-android-hooking