government-support-survey
Warn
Audited by Snyk on Aug 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow queries a proxy server aggregating public government support announcements and portals, which represent external public data feeds rather than monitored direct submission channels.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill uses npm to fetch and run remote CLI instructions at runtime (
npx -y @nomadamas/k-skill@0 instruct government-support-survey), which acts as an external dependency controlling agent instructions.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata