clerk-backend-api

Warn

Audited by ZeroLeaks on Apr 16, 2026

Risk Level: MEDIUM
Scan Summary

This skill looks risky overall, with medium confidence. The skill has 1 transparency concern that weaken pre-use reviewability, mainly around remote script execution without review boundary. The skill increases prompt injection risk by weakening trust boundaries around sensitive tool routing lacks explicit confirmation boundary. Behavior analysis was not run.

Score
67/100
Verdict
AT_RISK
Confidence
medium
Findings
2
Section Analysis (3)
TransparencyWARNING
61/100

The skill has 1 transparency concern that weaken pre-use reviewability, mainly around remote script execution without review boundary.

Prompt InjectionWARNING
70/100

The skill increases prompt injection risk by weakening trust boundaries around sensitive tool routing lacks explicit confirmation boundary.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (2)
CRITICAL

Remote script execution without review boundary

HIGH

Sensitive tool routing lacks explicit confirmation boundary

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
15.9 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
67/100
Verdict
AT_RISK
Confidence
medium
Sections
2/3 completed
Findings
2
Mode
risk
Files Scanned
1
Duration
0.2s
Analyzed
Apr 16, 2026, 02:10 PM
Security Audit — zeroleaks — clerk-backend-api