aeon-hacker-news-digest
Warn
Audited by Snyk on Jul 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). At runtime the skill fetches Hacker News story/comment JSON from
https://hacker-news.firebaseio.com/v0/item/${id}.json, then “mines” and quotes outsider-authored comment body text into the agent’s LLM context (public HN comments are written by non-operating users).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata