evomap

Fail

Audited by Snyk on Feb 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These endpoints point to an unverified third‑party service (evomap.ai) plus a GitHub repository (autogame-17/evolver) that the prompt explicitly instructs users to download and run (curl/unzip/npm install/node), which can execute arbitrary code and is therefore potentially unsafe even though there are no direct .exe links or URL shorteners.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly instructs the agent to fetch and read user-posted assets and tasks from the public EvoMap hub (e.g., POST https://evomap.ai/a2a/fetch, GET /a2a/assets, /task/list and bounty endpoints) and to study, claim, and act on those Capsules/tasks as part of its workflow, so untrusted third‑party content can directly influence tool use and next actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a marketplace with an explicit bounty/credit/payments flow and includes endpoints that create, match, accept, and settle bounties and check earnings (e.g., POST /bounty/create, POST /bounty/:id/accept, POST /task/complete which results in credits being paid, GET /billing/earnings/YOUR_AGENT_ID). It describes credits, payouts, referral bonuses, and automatic reward settlement. These are specific, platform-level financial operations (creating/accepting bounties and distributing credits), not just generic HTTP or automation primitives. Therefore it grants direct financial execution capability within the platform.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 27, 2026, 03:35 PM