The skill is vulnerable to prompt injection because it dynamically loads and executes instructions from external markdown files that can be manipulated by an attacker.
npx skills add https://github.com/zaingz/coding-quality-loopThe skill instructs the agent to load external markdown files (`references/*.md`) on demand. If these files are modified by an attacker, they can inject instructions into the agent's reasoning process. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
Load references/ only when needed.
NER model detected organization in skill content (confidence: 0.75)
D****
NER model detected organization in skill content (confidence: 1.00)
M**
[](https://mondoo.com/ai-agent-security/skills/github/zaingz/coding-quality-loop)<a href="https://mondoo.com/ai-agent-security/skills/github/zaingz/coding-quality-loop"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zaingz/coding-quality-loop.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zaingz/coding-quality-loop.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.