keel
Fail
Audited by Snyk on Aug 4, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). One URL is a direct GitHub "releases/latest/download" asset (https://github.com/modelcontextprotocol/registry/releases/latest/download/mcp-publisher_$) which is a direct-download of a release artifact from a small/unknown project and therefore matches high-risk indicators for distributing executables or installers.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Keel’s required runtime workflow ingests outsider-authored free text from the target repository by mechanically locating verification “surfaces” and carrying the literal
rawsnippets into LLM classification for each pending node.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata