consume-feed
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
sources/rss.py:fetch, the skill downloads an outsider-authored RSS feed (client.fetch_text(self.config.rss_url, ...)), parses the feed’s free-text fields (e.g.,entry.title,entry.summary/description) withfeedparser.parse(text), then ingests that content into Memory viafeed_storage.upsert_items/_memory_cmd("learn", ...).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata