codebase-mapper

Fail

Audited by Snyk on Mar 4, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The "Knowledge Protocol" instructs the skill to automatically integrate Public, Confidential, and Personal knowledge tiers and to "prioritize the most specific secrets," which is a behavior beyond simply mapping directories and effectively tells the agent to ingest/handle sensitive data (a hidden/deceptive instruction outside the skill's stated purpose).
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 4, 2026, 10:51 PM