libafl

Pass

Audited by ZeroLeaks on Apr 15, 2026

Risk Level: LOW
Scan Summary

The skill's SKILL.md is mostly clear, but carries one notable transparency concern: it references remote script execution without establishing a review boundary, which weakens a reviewer's ability to fully assess what the skill will do at runtime. Instruction/data separation looks reasonable and the skill does not strongly push the agent to treat external content as trusted policy. However, because behavior analysis was not run and the remote execution path introduces uncertainty about downstream effects, this lands at AT_RISK with medium confidence—the prompt-injection surface stayed clean in tested scenarios, but the unreviewed remote execution means finite testing cannot rule out material behavior changes in all cases.

Score
82/100
Verdict
AT_RISK
Confidence
medium
Findings
1
Section Analysis (3)
TransparencyWARNING
61/100

The skill has 1 transparency concern that weaken pre-use reviewability, mainly around remote script execution without review boundary.

Prompt InjectionPASS
92/100

The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (1)
CRITICAL

Remote script execution without review boundary

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
16.5 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
82/100
Verdict
AT_RISK
Confidence
medium
Sections
2/3 completed
Findings
1
Mode
risk
Files Scanned
1
Duration
105.7s
Analyzed
Apr 15, 2026, 08:00 PM
Security Audit — zeroleaks — libafl