skill-index
Warn
Audited by Snyk on May 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs use of the agent-browser skill and browser shortcuts (e.g., agent-browser can open/scrape arbitrary URLs and the xhs.yaml/douyin.yaml/tiktok.yaml shortcuts act on public social platforms and example URLs like https://v.douyin.com/xxx), so the agent fetches and interprets untrusted, user-generated web content that can influence its actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata