repo-bible
Warn
Audited by Snyk on May 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflows (workflows/generate-bible.md and workflows/refresh-bible.md) and references/research-protocol.md explicitly instruct the agent/operator to "browse current sources" (competitor sites, pricing pages, docs, policies) and to extract external source URLs via scripts/repo-bible sources, meaning untrusted public web content is expected to be read and used to update requirements, roadmap, and decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata