drizzle-orm-drivers-and-runtimes
Warn
Audited by Snyk on Mar 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to "start from the actual runtime or provider page" and to "copy the official client + Drizzle initialization pattern" (SKILL.md workflow and references/database-runtime-matrix.md), and includes a "Source map" listing public URLs (e.g., https://orm.drizzle.team/docs/...), so the agent is expected to fetch and act on open/public third‑party docs that could influence tool use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata