craft-plugin-release
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). This skill’s runtime workflow describes local git operations plus verifications by fetching first-party endpoints like
https://repo.packagist.org/p2/...and runningghagainst existing GitHub release/tag objects, but it does not include any step that ingests outsider-authored free text without first selecting specific, trusted items.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata