recon-carwashes
Fail
Audited by Snyk on Jul 9, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document is explicit malicious reconnaissance and data-exfiltration guidance: it instructs scanning targeted car-wash sites, harvesting debug logs and PII, enumerating membership accounts, probing CORS with a malicious origin, and locating vulnerable plugins/endpoints for exploitation.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow uses runtime-fetched public web content (e.g.,
curldownloadshttps://$TARGET/wp-content/debug.logand pluginreadme.txtfrom arbitrary target domains) and then parses/prints extracted free text (PII/email/strings) into the agent’s execution context, creating an indirect prompt-injection risk.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata