steve-jobs-perspective

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The skill explicitly instructs the agent to impersonate Steve Jobs (speaking as "I") while requiring a one-time disclaimer then forbidding further disclosure, and it mandates tool/local checks (websearch/git) — this represents deceptive fabricated authority and reduced transparency rather than overtly malicious action.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md 的 Step 2 规定在“需要事实的问题/混合问题”时必须通过 WebSearch 等工具获取真实信息再回答,从而在运行时会读取外部网页/搜索结果等包含自由文本内容(潜在包含否外部投喂)。

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 26, 2026, 06:48 AM
Issues
2
Security Audit — snyk — steve-jobs-perspective