svelte-runes
Fail
Audited by Snyk on Apr 26, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (medium risk: 0.60). The file contains a hidden HTML-comment block with LLM workflow and maintainer commands (e.g., "LLM WORKFLOW" and "Run: npx skills add . --list") that are unrelated to Svelte guidance and are concealed from normal readers, so they are hidden/deceptive instructions outside the skill's stated purpose.
Issues (1)
E004
CRITICALPrompt injection detected in skill instructions.
Audit Metadata