hol-guard
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow uses
plugin-scanner lint/verify(e.g.,plugin-scanner lint ./plugin-scanner verify .) to scan local plugin/skill/package files that are authored by the provider user (outsider to the agent), creating an injection surface through free text contained in those files.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata