weekly-report-onboard
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Step 3/4 of weekly-report-onboard ingests “past reports” provided by the user (pasted text or file paths) and then extracts the format/tone from that content, so outsider-authored free text can be read by the required runtime workflow.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's runtime CLI is invoked with "uvx --from git+https://github.com/mjkimR/weekly-report@v0.2.0", which fetches the package from that GitHub URL and executes its code at runtime, so it is a required external dependency that runs remote code.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata