ir-playbook
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s runtime workflow is driven by user-provided incident context (e.g., SIEM/EDR alert text, log entries, email headers, and other incident artifacts) that can include attacker-controlled free text; this content is then incorporated into the agent’s LLM context for classification/report generation, creating an indirect prompt-injection exposure path.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). The playbook instructs privileged, state-changing actions (isolating networks, disabling accounts, modifying firewall rules, deleting malicious files, imaging disks, shutting down hosts, rotating/revoking credentials, etc.) that would modify the machine or environment and require elevated privileges, even though it frames them as human-driven actions and includes a safety notice; therefore it pushes toward compromising system state.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata