exploiting-deeplink-vulnerabilities

Fail

Audited by Snyk on Mar 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content is dual-use but contains explicit, actionable exploit instructions for data exfiltration and intent hijacking (e.g., javascript:fetch to external "evil.com" with document.cookie, token/callback exfiltration payloads, and guidance to create a malicious app registering the same URL scheme), which are deliberate abuse patterns enabling credential theft and link hijacking.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 15, 2026, 01:28 PM
Issues
2