web-vuln-idor

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This skill is an explicit offensive IDOR exploitation toolkit that instructs unauthorized access, mass enumeration/exfiltration of PII, and account-takeover (ATO) techniques — high abuse potential.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests free text from the target system’s HTTP responses and also sends attacker-supplied identifiers (e.g., SECSKILL_RESOURCE_ID/SECSKILL_ENDPOINT) into requests without first selecting a specific trusted item, meaning an outsider can influence LLM-readable content via the target’s endpoints (including probed GraphQL responses that are parsed/grep’d for sensitive fields).

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 19, 2026, 06:15 AM
Issues
2
Security Audit — snyk — web-vuln-idor