tracer-dev
Fail
Audited by Snyk on Feb 21, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The workflow contains an explicit, mandatory instruction to perform commits and state updates through a specific remote "background agent" (openrouter/z-ai/glm-4.7-flash), which constitutes a deliberate channel that can exfiltrate repository contents, secrets, or modify history—this is a high-risk supply-chain/data-exfiltration/backdoor pattern; aside from that, the rest of the skill is procedural and not directly malicious.
Audit Metadata