quality-retrospective

Fail

Audited by Snyk on Apr 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The spawn message for the context agent includes a "MANDATORY FIRST STEPS" instruction to read ~/.codex/agents/cli-explore-agent.md which is not a phase artifact and thus is an extra, out-of-scope directive that could alter agent behavior (i.e., a concealed/deceptive instruction outside the skill's stated purpose); no other hidden or obfuscated injections were found.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 17, 2026, 01:13 AM
Issues
1