project
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md의 Phase 2 Plugin Inventory Scan은
~/.claude/plugins/및~/.codex/plugins/내 로컬plugin.json/SKILL.md메타데이터를 스캔해 인벤토리를 구성하지만, 외부(제3자) 텍스트를 LLM이 자유 서술로 읽는 런타임 워크플로우가 필수로 정의되어 있지 않습니다.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata