Warn
Audited by Snyk on Apr 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly reads and processes email message bodies from third-party sources via IMAP/himalaya and Apple Mail SQLite (see SKILL.md, himalaya.md "himalaya message read" / "envelope list -o json", and apple-mail.md queries) and uses that content in workflows (searching, composing replies, sending), so untrusted user-generated email could indirectly inject instructions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata