install-from-catalog
Warn
Audited by Snyk on Sep 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill fetches and installs third-party repositories and packages from user-supplied or catalogued sources (such as GitHub repositories via
npx skills addor guide URLs), which can contain outsider-authored text in READMEs, instructions, and skill definitions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata