Angular v22 Node Compatibility Gate
Warn
Audited by Snyk on Jul 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required workflow includes “Read the exact Angular 22 documentation or changelog entry” (public web/GitHub content) at runtime, which is outsider-authored free text that could be ingested into the agent’s LLM context.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The Procedure explicitly instructs the agent at runtime to "Read the exact Angular 22 documentation or changelog entry" and the skill provides these external URLs (https://blog.angular.dev/announcing-angular-v22-c52bb83a4664, https://angular.dev/roadmap, https://github.com/angular/angular/blob/main/CHANGELOG.md), so fetching those pages would directly control the agent's claims and behavior.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata