dev-setup

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and interprets public third‑party documentation as part of its required workflow (Step 3 & Step 5: "Try Context7 first... fallback (WebFetch): https://vitejs.dev/config/server-options.html" and fallback to "https://github.com/coderabbitai/git-worktree-runner"), and those external pages are used to influence configuration and generated scripts, so untrusted web content could indirectly inject instructions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 12:28 PM
Issues
1
Security Audit — snyk — dev-setup