ops-chutes

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill calls external services (INFERENCE_API_BASE "https://llm.chutes.ai" and MANAGEMENT_API_BASE "https://api.chutes.ai" from util.py) and manager.py directly consumes their responses (e.g., list_models/list_inference_models, timed_ping, get_chute_details, get_usage_history) to drive logic and recommendations (notably the recommend command), so untrusted third‑party API responses can materially influence agent decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:37 AM
Issues
1
Security Audit — snyk — ops-chutes