smart-delegation

Fail

Audited by Snyk on Mar 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill explicitly instructs inlining workspace identity, user memory, and conversation context into sub-agent spawn prompts (including third-party models), creating a clear, intentional path for sensitive data to be sent externally — a high-risk data-exfiltration pattern; no hidden exec/obfuscation/backdoor code or credential-harvesting routines are present.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 7, 2026, 03:11 AM