skill-forge
Warn
Audited by Snyk on Aug 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). skill-forge ingests outsider-authored free text by letting the user provide a URL for Phase 1A and then “crawl”/fetch that content (README/docs/api/changelog/etc.) for research before writing the generated SKILL.md.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill instructs the agent at runtime to fetch and crawl external documentation (e.g. the repo URL "https://github.com/resendlabs/resend-node" and multiple Resend docs like "https://resend.com/docs/introduction", "https://resend.com/docs/api-reference/introduction", "https://resend.com/llms.txt", "https://resend.com/docs/api-reference/emails/send"), and that fetched content is used to generate the SKILL.md (i.e., directly controls the agent's prompts/output), so these URLs are runtime dependencies that influence agent behavior.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata