install-skill
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The
install-skillworkflow accepts an operator-provided${var}(aowner/repoGitHub pack reference) and then fetches that outsider-authored repo tarball at runtime, readingskills-pack.json/skills/*/SKILL.mdfor scanning and installation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata