riff

Fail

Audited by Snyk on Mar 29, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill contains multiple intentional data-exfiltration / token-use patterns (CLI calls that "use subscription tokens", sending auth tokens to configurable endpoints via query strings/Authorization headers, and broadcast postMessage('*') of error payloads) that create clear avenues for credential misuse or leaking sensitive runtime data to untrusted servers.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 29, 2026, 07:25 PM
Issues
1