consume-feed

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In sources/rss.py:fetch, the skill downloads an outsider-authored RSS feed (client.fetch_text(self.config.rss_url, ...)), parses the feed’s free-text fields (e.g., entry.title, entry.summary/description) with feedparser.parse(text), then ingests that content into Memory via feed_storage.upsert_items/_memory_cmd("learn", ...).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:03 PM
Issues
1
Security Audit — snyk — consume-feed