meteor-debugging
Warn
Audited by Snyk on Aug 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Although the workflow reads user-provided app logs/evidence and may analyze browser trace/Playwright reports from the user’s chosen scope, the skill does not describe any required runtime behavior where outsider-authored free text from a third-party feed/queue (e.g., email/inbox/chat/GitHub/Jira/ticket/comment submission) is ingested without first selecting a specific trusted item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata