progress-tracking

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill proactively and persistently captures workspace context, changed files, git metadata, and other checkpoints without consent—behavior that can lead to unauthorized disclosure of secrets or sensitive data (even though no explicit external endpoint is shown), so it represents a high privacy/exfiltration risk.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 02:40 AM