context-mode-ops

Warn

Audited by Snyk on May 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflows (e.g., validation.md, review-pr.md, triage-issue.md, marketing.md) explicitly instruct agents to fetch and verify information from public third-party sources — using WebSearch, ctx_fetch_and_index/Context7, and GitHub API/gh commands to read external docs, web pages, issues, and release data — and those external, user-generated or public documents are used to make verification, triage, and merge/release decisions, which could allow indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 16, 2026, 08:50 PM
Issues
1
Security Audit — snyk — context-mode-ops