trigger-string-evasion

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). Code constructs eval via string concatenation (window['ev' + 'al']) and invokes it dynamically, an obfuscation/evasion technique that enables remote code execution and is therefore a high-risk pattern even if the current payload is just an alert.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 03:36 AM