sd-paper-detail
Fail
Audited by Snyk on Mar 5, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill contains deliberate anti-bot and CAPTCHA-bypassing techniques (overriding navigator.webdriver, auto-clicking Cloudflare Turnstile via accessibility snapshots and cross-origin iframe interaction) that are intended to evade access controls and enable abusive scraping; no direct data-exfiltration, credential theft, remote code execution, or backdoor constructs were found.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). The skill explicitly instructs bypassing bot-detection measures (setting navigator.webdriver, auto-clicking Cloudflare Turnstile) which is an attempt to circumvent security mechanisms and thus a high-risk instruction to manipulate the runtime/browser state.
Audit Metadata