dual-axis-skill-reviewer

Warn

Audited by Snyk on Jun 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The skill reads and ingests OUTSIDER-authored free text from the target project’s skills/*/SKILL.md (and related scripts/*.py / references/*.md) via score_skill()skill_file.read_text() and child.read_text(), then embeds that content into the generated LLM prompt in build_llm_prompt() (indirect prompt injection risk).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 01:21 PM
Issues
1
Security Audit — snyk — dual-axis-skill-reviewer