Back to skill
Skillv2.0.1

Static analysis security

Karma Project Manager · Deterministic local checks for risky code patterns and metadata mismatches.

Scanner verdict

SuspiciousApr 30, 2026, 5:12 AM
Summary
Detected: suspicious.generated_source_template_injection
Reason codes
suspicious.generated_source_template_injection
Engine
v2.4.5

Evidence

criticalSKILL.md:19
User-controlled placeholder is embedded directly into generated source code.
suspicious.generated_source_template_injection