social-calendar-builder

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In SKILL.md, the skill’s runtime reads user-provided free text contained in pasted “analytics exports, trend reports, and any scraped page” as untrusted input (via “Reads” from own analytics exports and “Trend inputs” from trend-spotter telemetry), which can be authored by an outsider and is LLM-ingested for planning/recycle/trend decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 07:29 PM
Issues
1
Security Audit — snyk — social-calendar-builder