migrate-divi-to-gutenberg

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly reads and parses user-generated WordPress content via calls like wordpress_list_pages / wordpress_list_posts and wordpress_extract_builder_content to ingest Divi shortcodes from site posts/pages, and then uses that parsed content to drive migration decisions and actions (mapping modules, flagging items, creating duplicates), so untrusted third-party content can materially influence the agent's behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 05:28 PM
Issues
1
Security Audit — snyk — migrate-divi-to-gutenberg