brand-guide
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads selected, user-provided WordPress theme files from a local theme-path (CSS/PHP) via
scripts/extract-brand.pyand extracts their free-text contents (colors/fonts/theme metadata), which could include attacker-authored strings.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill includes explicit commands to run local scripts under /root and to execute docker exec wp-cli commands that create/update WordPress content (modifying container/host state and files under /root), so it directs the agent to change the machine/container state.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata