fnox-providers
Warn
Audited by Snyk on Jun 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow for this skill is to read
fnox.tomland then fetch secrets from configured providers (e.g., AWS/GCP/Azure/Vault/Doppler/1Password/Bitwarden/Infisical); those provider responses are outsider-authored free-form secret values that the agent ingests into the LLM context when it uses the fetched secret text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata