mcp-management
Warn
Audited by Snyk on Apr 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly configures and connects to external MCP servers (e.g., .claude/.mcp.json referencing @modelcontextprotocol/server-brave-search, server-puppeteer/server-fetch and tools like playwright_screenshot which accept arbitrary URLs) and the workflow/docs (references/gemini-cli-integration.md and SKILL.md examples) show the agent discovering, fetching, and acting on open web pages/search results, so untrusted third‑party content is ingested and can influence tool selection and subsequent actions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's runtime config and examples use npx to launch MCP servers (e.g., "npx -y @modelcontextprotocol/server-memory" and similar @modelcontextprotocol/server-* packages), which causes remote npm packages to be fetched and executed at runtime (see https://www.npmjs.com/package/@modelcontextprotocol/server-memory and https://github.com/modelcontextprotocol/servers), and those servers directly provide/execute tools/prompts the agent depends on.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata