target-recon
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to search and fetch content from public sources (GitHub repos to clone and read, npmjs/npm search results, grep.app searches, and PyPI/pypi.org pages) and to read/interpret READMEs, CHANGELOGs and SECURITY.md as required steps that directly influence target selection and follow-up actions, exposing the agent to untrusted third-party content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata