blueprint

Warn

Audited by Snyk on Mar 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's blueprint workflow explicitly accepts and fetches external, public resources — e.g., "resource": "url", "git:directory" (GitHub) and "wordpress.org/plugins" in the "Resource References" and steps like "installPlugin", "writeFile" (data from a url), and "request" — meaning untrusted third-party content is ingested and can influence execution (installed plugin/theme code or fetched files) at runtime.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 02:22 PM
Issues
2