auditing-tls-certificate-transparency-logs
Warn
Audited by Snyk on Apr 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly queries and ingests public, untrusted Certificate Transparency data from crt.sh and CT log servers (see SKILL.md "Query crt.sh" and scripts/agent.py functions query_crtsh/get_certificate_detail) and then uses those results to discover subdomains and generate/drive alerts and notifications, so third‑party content directly influences agent decisions and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata