ir-playbook

Warn

Audited by Snyk on Jul 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The skill’s runtime workflow is driven by user-provided incident context (e.g., SIEM/EDR alert text, log entries, email headers, and other incident artifacts) that can include attacker-controlled free text; this content is then incorporated into the agent’s LLM context for classification/report generation, creating an indirect prompt-injection exposure path.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). The playbook instructs privileged, state-changing actions (isolating networks, disabling accounts, modifying firewall rules, deleting malicious files, imaging disks, shutting down hosts, rotating/revoking credentials, etc.) that would modify the machine or environment and require elevated privileges, even though it frames them as human-driven actions and includes a safety notice; therefore it pushes toward compromising system state.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 2, 2026, 01:37 PM
Issues
2
Security Audit — snyk — ir-playbook