cors-credential-wordpress

Fail

Audited by Snyk on Jul 31, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document intentionally details step-by-step exploitation of CORS misconfigurations for cross-origin data exfiltration and account takeover (cookie theft/replay), indicating deliberate malicious intent.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The skill’s workflow reads outsider-authored free text only insofar as it issues HTTP requests to a user-supplied TARGET and attacker-supplied Origin/page content, but at runtime it primarily ingests first-party server responses (WordPress API outputs) rather than any free-text the outsider “submits” into a monitored queue/feed; it does not describe consuming chat/email/tickets/issues or other outsider-posted text sources.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 31, 2026, 04:47 PM
Issues
2
Security Audit — snyk — cors-credential-wordpress