codex-skin-pack-installer

Warn

Audited by Snyk on Jul 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). The workflow runs scripts/fetch_skin_pack.py, which downloads outsider-authored release ZIP content from a public GitHub URL at runtime and extracts theme.json/README.md-like text into the staged folder; that content is then used for subsequent “apply”/verification steps and can be ingested by the agent as readable text (indirect prompt injection via fetched pack contents).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 23, 2026, 06:39 AM
Issues
1
Security Audit — snyk — codex-skin-pack-installer