reality-check-sparta

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill actively fetches and parses live public web pages (e.g., adversarial.py's verify_url_fresh and run_fresh_verification use httpx to re-fetch MITRE ATT&CK URLs and adversarial.check_url_file_alignment reads downloaded HTML from the urls/url_content tables), and those external contents are directly inspected by cli.py's run_check and related workflows to determine PASS/FAIL, suggest fixes, and trigger regeneration, so third‑party page content can materially influence tool decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:38 AM
Issues
1
Security Audit — snyk — reality-check-sparta