launch-asset-packager

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). This required workflow ingests and reads user-provided asset lists/store-console exports and “store listing” fields from the user’s store-console exports, which are not necessarily first-party/trusted and therefore provide an outsider submission path of free text into runtime context the skill processes into manifest/spec drafts.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 07:30 PM
Issues
1
Security Audit — snyk — launch-asset-packager