pi-mcp-adapter

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). Yes — the skill explicitly connects to arbitrary MCP servers and HTTP/SSE endpoints (see "HTTP/SSE Servers" and the mcpServers examples), reads external resources via mcp({ action: "read-resource" }) ("Working with Resources"), and fetches/handles UI HTML and messages from _meta.ui.resourceUri using mcp({ action: "ui-messages" }) ("UI Communication Flow"), so untrusted third‑party content can directly influence tool discovery and the agent's subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 05:45 PM
Issues
1
Security Audit — snyk — pi-mcp-adapter