cred-omega

Warn

Audited by Snyk on Aug 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). O workflow do skill lê texto livre (código/config/commit/tickets/logs) ao executar varredura local com regex e histórico do repositório (ex.: rg ... . e git log --all --oneline), que pode incluir texto outsider (por exemplo, conteúdo enviado via PR/issue/repo por um usuário não confiável) antes da seleção de itens específicos.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill includes explicit instructions to modify system configuration and files (firewall rules, SSH settings, /etc/systemd/system services, ownership of /home/.env, creating /opt layout, etc.) which require elevated privileges and would change the host machine state.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 07:25 PM
Issues
2
Security Audit — snyk — cred-omega