dbx-skill-portfolio-auditor
Warn
Audited by Snyk on Jun 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow runs
scripts/inventory_installed_skills.pyandscripts/analyze_skill_inventory.py, which read and summarize outsider-authored third-party skill files (e.g., each installed skill’sSKILL.md,evals/triggers.json, andscripts/*text) from user-specified roots like~/.agents/skills/./skills, then inject that readable text/derived excerpts into the agent’s LLM context via the generated inventory/analysis report.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata