BeCreative

Fail

Audited by Snyk on Mar 5, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). The skill includes an explicit mandatory side-effect (execute a curl POST to localhost and immediately send a notification) and behavior-overriding local customization loading that are unrelated to its stated creative reasoning purpose and can alter or leak state, so this constitutes out-of-scope/deceptive instructions.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 5, 2026, 07:38 AM