obsidian-plugin-release
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The workflow’s runtime path fetches and ingests repository files for lint/build/release (e.g.,
bun run build,bunx eslint src/fromscripts/release.ts), and those files (notablymanifest.json,versions.json,main.js, etc.) are outsider-authored free text because they come from the plugin’s repository contents that the operating user did not author via this skill.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata