web-app-security

Fail

Audited by Snyk on Apr 11, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The content is a dual-use offensive security guide that includes explicit, actionable instructions for data exfiltration, credential theft, post‑exploitation backdoors (webshell/plugin/theme modification), remote command execution, and evasion techniques, which collectively present a high risk of deliberate malicious abuse.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's required workflow and references explicitly instruct fetching and analyzing open web targets and public endpoints (e.g., scanning and curl/kr scan commands, checking /swagger.json, /wp-json, and using Burp to intercept site pages) so the agent ingests and interprets untrusted, user-controlled web content to drive testing and follow-up actions.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 11, 2026, 06:20 PM
Issues
2
Security Audit — snyk — web-app-security