claw-shell-hardened
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's runtime (handler.js sendCommand/readOutput) executes arbitrary shell commands and returns their output to the agent, and SKILL.md even lists examples like "bird read https://x.com/..." — meaning the agent can fetch and ingest untrusted public web/social content that could contain instructions and materially influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata