sap-cap-upgrade

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly queries public third‑party services — it runs npm view <pkg> dist-tags.latest (Step 3) and calls advisory sources (osv.dev and the npm advisory bulk fallback) as the vulnerability gate (Step 3.5) per SKILL.md, ingesting untrusted npm/advisory content which the agent interprets to decide whether to block or proceed with upgrades.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 03:06 PM
Issues
1
Security Audit — snyk — sap-cap-upgrade