cors-credential-wordpress
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document intentionally details step-by-step exploitation of CORS misconfigurations for cross-origin data exfiltration and account takeover (cookie theft/replay), indicating deliberate malicious intent.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill’s workflow reads outsider-authored free text only insofar as it issues HTTP requests to a user-supplied TARGET and attacker-supplied Origin/page content, but at runtime it primarily ingests first-party server responses (WordPress API outputs) rather than any free-text the outsider “submits” into a monitored queue/feed; it does not describe consuming chat/email/tickets/issues or other outsider-posted text sources.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata