cpanel-deploy
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill shows and requires embedding plaintext credentials/tokens verbatim in CLI commands and config operations (e.g., deploy:wp with a literal DB password, db:user-create with a password placeholder, git clone needing a token, writing/reading .env or wp-config), so an LLM following it would need to handle/output secrets directly.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Skill “cPanel — Deploy mã nguồn” chủ yếu chỉ thao tác file ops và khởi tạo deployments theo URL do người dùng cung cấp (ví dụ deploy:wp tải wordpress.org/latest.zip và file ops như file:save/read), không có bước trong mô tả cho thấy agent phải đọc free text do outsider đăng vào một feed/queue/issue/ticket hay nguồn người ngoài “post” vào mà không được chọn cụ thể.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill clearly fetches remote code/artifacts at runtime (e.g., "wordpress.org/latest.zip" in SKILL.md:31 and "https://github.com/user/repo.git" in SKILL.md:113) which are required dependencies that will result in remote code being deployed/executed on the host.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata