wix-manage

Warn

Audited by Snyk on May 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly ingests external, user-provided URLs/images (see references/blog/how-to-create-blog-posts.md — "Identify external image URLs from user input" and import via Import File API) and the mandatory "Create Product from Image" flow (SKILL.md / references/stores/create-product-from-image.md) combines Media Upload + LLM analysis, meaning untrusted third-party content is fetched and analyzed as part of runtime decision-making.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes payment-related APIs and operations. It exposes "Create Payment Links" (creates payment links to collect payments), "Payment Links for Bookings" (links booking IDs to payment requests), and "How to Setup Wix Payments" (configures Wix Payments, including business verification and bank account setup/payment method configuration). These are specific payment gateway and payment-collection operations (i.e., designed to move money or configure payment provider details), not generic tooling. Therefore it grants direct financial execution capability.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 10:42 AM
Issues
2
Security Audit — snyk — wix-manage