general
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the assistant to search and present results from public community registries (ClawHub and skills.sh) and to install community skills via
golembot skill search/golembot skill add, which means it will fetch and interpret untrusted third‑party registry content that can materially influence actions (skill installation).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata