catalog-babysitter-users
Warn
Audited by Snyk on Jul 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes—this skill runs
gh search codeandgh api repos/<owner>/<name>against public GitHub repositories, then ingests the returned repository metadata and matching file paths (outsider-authored free text) into the generated markdown catalog that is fed back into the agent’s LLM context during the run.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata