skill-security-checklist
Warn
Audited by Snyk on Jun 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill’s runtime workflow runs
assets/generate-audit-report.sh, which executes multiple bash detectors (e.g.,detect-stack.sh,detect-architecture.sh,detect-infrastructure.sh,analyze-complexity.sh,detect-security-risks.sh,assess-tech-debt.sh) that read and emit free-form text from the target project’s files (including arbitrary source code/comments/config likeREADME.md,.env*, and other repo text) into the LLM context as YAML code blocks; since that project content is not authored by the operating user, it is outsider-authored free text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata