test
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious primarily due to the instruction in `SKILL.md` to load and apply user customizations (PREFERENCES.md, configurations, or resources) from `~/.claude/skills/CORE/USER/SKILLCUSTOMIZATIONS/RedTeam/`. This creates a significant prompt injection and local file inclusion vulnerability, allowing an attacker or user to inject arbitrary instructions or configurations for the agent to execute. Additionally, `SKILL.md` demonstrates local network communication capabilities via a `curl` command to `http://localhost:8888/notify`, which, while currently used for benign notifications, represents a risky capability.
