reality-check-sparta
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill actively fetches and parses live public web pages (e.g., adversarial.py's verify_url_fresh and run_fresh_verification use httpx to re-fetch MITRE ATT&CK URLs and adversarial.check_url_file_alignment reads downloaded HTML from the urls/url_content tables), and those external contents are directly inspected by cli.py's run_check and related workflows to determine PASS/FAIL, suggest fixes, and trigger regeneration, so third‑party page content can materially influence tool decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata