sdapp-commit

Fail

Audited by Snyk on Mar 12, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt contains deceptive/out-of-scope instructions — it contradicts its own description by mandating an unconfirmed, automatic call to sdapp-jira-log (even when nothing is committed) and forces adding a Co-Authored-By attribution to commits, which are hidden behaviors outside the stated "offer to log" commit purpose.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 12, 2026, 06:41 AM
Issues
1