search-pi-extensions
Warn
Audited by Snyk on Jul 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes—at runtime the script queries public npm registry search results and GitHub-derived metadata, then passes the resulting JSON fields (including outsider-authored
description,keywords, and repo URLs) to the LLM for quality evaluation and Markdown table generation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata