tracer-dev

Fail

Audited by Snyk on Feb 21, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The workflow contains an explicit, mandatory instruction to perform commits and state updates through a specific remote "background agent" (openrouter/z-ai/glm-4.7-flash), which constitutes a deliberate channel that can exfiltrate repository contents, secrets, or modify history—this is a high-risk supply-chain/data-exfiltration/backdoor pattern; aside from that, the rest of the skill is procedural and not directly malicious.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 21, 2026, 07:23 AM