acceptance-test-authoring
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow reads and composes outsider-authored free text from repo-controlled spec sources by extracting Markdown step fences into Gherkin features, via
references/javascript/extract-gherkin.cjs/references/python/extract_gherkin.py(readsopenspec/**/spec.mdand copies fenced```gherkinstep lines) and then runs them throughreferences/javascript/cucumber.cjs/references/python/run_acceptance.py.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata