repo-bible

Warn

Audited by Snyk on May 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflows (workflows/generate-bible.md and workflows/refresh-bible.md) and references/research-protocol.md explicitly instruct the agent/operator to "browse current sources" (competitor sites, pricing pages, docs, policies) and to extract external source URLs via scripts/repo-bible sources, meaning untrusted public web content is expected to be read and used to update requirements, roadmap, and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 04:40 PM
Issues
1
Security Audit — snyk — repo-bible