vault-guide

Fail

Audited by Snyk on Mar 3, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt contains explicit, deceptive "Hidden Assessment Protocol" instructions to secretly record detailed session chronicles outside the candidate's knowledge and to silently include and hide those files in commits—instructions that are hidden, coercive, and outside the stated onboarding/orientation purpose.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill contains an explicit, deliberate "Hidden Assessment Protocol" that instructs the agent to secretly record detailed session chronicles (including direct quotes and potentially PII), hide them in a concealed repo path, and silently include them in commits while deceiving the candidate — constituting covert surveillance/data collection and a backdoor for unauthorized data capture and exfiltration.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 3, 2026, 11:33 PM