doko
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's core commands (/doko read and /doko search) explicitly fetch and return content from arbitrary external web pages and search results via the Dokobot API endpoints (e.g., https://dokobot.ai/api/tools/read and /api/tools/search) as described in SKILL.md, so untrusted third-party page content is ingested and used for analysis.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata