wordpress-full-compromise
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). Contains explicit, actionable instructions to register an account, intercept a Mailinator password-reset link, and set a new password—facilitating unauthorized account takeover and clear abuse potential.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
references/mailinator-reset-workflow.md, the runtime workflow ingests outsider-authored free text by reading the full HTML body of an email from Mailinator (“Read the message body” and then regex-extractingwp-login.php?action=rp&key=...&login=...), which is attacker-submitted via the target’s email process.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata