setup-weaverse-project

Fail

Audited by Snyk on Aug 21, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill explicitly asks for/store storefront and builder API tokens (PUBLIC_STOREFRONT_API_TOKEN, WEAVERSE_API_KEY, etc.) and instructs the agent to write them into .env or an MCP client env block, which requires the agent to accept and embed secret values verbatim—creating an exfiltration risk.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill explicitly instructs an agent to obtain and use sensitive API keys, run remote npm tooling (npx -y), and perform automated GitHub pushes and read/write/delete operations on a user's project — actions that enable backdoor access and unauthorized modification/exfiltration if misused.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md’s required runtime workflow reads user-supplied free text via the “setup prompt” fields (e.g., Theme handle, WEAVERSE_PROJECT_ID copied from Builder, and Shopify domain/token inputs) to generate and populate local .env and to run/verify commands.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 21, 2026, 06:44 AM
Issues
3
Security Audit — snyk — setup-weaverse-project