docsync-setup
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow for this skill uses project-local Claude Code hooks (
assets/docsync-track.mjs,assets/docsync-watch.mjs,assets/docsync-gate.mjs) that ingest free text from outsider-authored.mdfiles in the workspace at runtime (viareadFileSync(...)parsing frontmatter and viast.touchedpaths recorded on toolRead/Write/Edit), enabling indirect prompt injection through thelast_updated/sync_procedure/frontmatter content of those documents.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata