astryx
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The runtime workflow ingests only first-party, trusted component/template/doc content from the Astryx MCP/CLI (e.g.,
search(query)/get(name)), and it does not ingest outsider-authored free text unless the user explicitly provides it as a specific component/template/doc query for retrieval.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill documents an MCP server that is queried at runtime by AI tools (e.g., Cursor/Claude) to fetch component/docs, so the external URL https://astryx.atmeta.com/mcp can directly control agent prompts by supplying model context at runtime.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata