network-security

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's referenced runbooks explicitly fetch and ingest public third-party data as part of normal workflow—for example references/ddos.md shows curling Cloudflare's IP lists (https://www.cloudflare.com/ips-*) and references/ids-ips.md instructs running suricata-update to pull ET Open rules—so the agent is expected to consume untrusted public web content that can materially alter firewall/IDS actions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill contains explicit privileged operations and file edits (apt installs, systemctl enable/reload, ufw/nftables changes, editing /etc/ssh/sshd_config, creating files under /etc, certbot, etc.) that instruct modifying system state and require root/sudo, so it should be flagged.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 11:14 AM
Issues
2
Security Audit — snyk — network-security