project-health-check

Fail

Audited by Snyk on Mar 4, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). The Knowledge Protocol line instructs the skill to automatically integrate and "prioritiz[e] the most specific secrets" from Public, Confidential, and Personal tiers—an explicit directive to access and favor secrets that is unnecessary for a project health audit and could enable hidden data access or exfiltration despite the claim of "no leaks," so it is a deceptive/out-of-scope instruction.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 4, 2026, 11:21 PM