fuzzlyn-triage
Warn
Audited by Snyk on May 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill requires the agent to ask for a link to a Fuzzlyn CI run and then download and extract Issues_{platform}_Checked.zip artifacts and a Helix payload (via runfo) from that CI run, meaning it ingests external, user-provided CI artifacts and playback files which the agent must read and act upon to drive triage steps.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill instructs downloading and running a Helix payload at runtime via the command "runfo get-helix-payload -j -w Partition0 -o " which fetches remote corerun/superpmi/mcs binaries that are executed locally, so external fetched code is a required runtime dependency.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata