superdesign

Fail

Audited by Snyk on Mar 6, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill content mandates automatically fetching remote instructions, installing and running a third‑party CLI, and uploading full source files (including potentially sensitive code/config) to an external service without explicit user consent — creating clear vectors for data exfiltration and supply‑chain compromise.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 6, 2026, 05:33 PM