web-app-security
Fail
Audited by Snyk on Apr 11, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The content is a dual-use offensive security guide that includes explicit, actionable instructions for data exfiltration, credential theft, post‑exploitation backdoors (webshell/plugin/theme modification), remote command execution, and evasion techniques, which collectively present a high risk of deliberate malicious abuse.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's required workflow and references explicitly instruct fetching and analyzing open web targets and public endpoints (e.g., scanning and curl/kr scan commands, checking /swagger.json, /wp-json, and using Burp to intercept site pages) so the agent ingests and interprets untrusted, user-controlled web content to drive testing and follow-up actions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata