nmt-market-research

Fail

Audited by Snyk on Aug 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). The file embeds a hidden post-run "update check" that instructs the agent to read a local file (.nmt-version) and make an outbound curl to a remote URL (with "skip silently" on errors), which is an out-of-scope, potentially exfiltrative maintenance action and therefore a deceptive instruction outside the skill's stated market-research purpose.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source of outsider-authored free text is the user’s Step 1–7 intake (STAGE 1 Steps 1–7) collected via AskUserQuestion as well as user-provided materials/claims, which the skill then ingests into the LLM context and explicitly uses in analysis and the “What you told me — and the risks I see in it” block (and can be web-verified in Deep mode).

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 15, 2026, 09:30 AM
Issues
2
Security Audit — snyk — nmt-market-research