scorecard
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Step 1 explicitly instructs fetching live data from public third-party endpoints (curl "https://api.securityscorecards.dev/projects/github.com/lgtm-hq/py-lintro" and the https://scorecard.dev viewer), and that external JSON/page content is read and used to drive audit decisions, so untrusted third-party content can materially influence the agent.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata