discourse
Warn
Audited by Snyk on May 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly uses the Membrane connector to fetch and list Discourse forum content (e.g., "List Topic Posts", "Get Post", "List Latest Topics" in SKILL.md), meaning the agent will read untrusted, user-generated forum posts that could influence its subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata