nemoclaw-contributor-update-dependencies
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill “Update Dependencies” ultimately runs
scripts/collect-release-ledger.py, which reads upstream dependency evidence (release notes/changelogs/commit messages/changed paths and optional GitHub release/tag listings) from external repositories and GitHub APIs; that read path ingests outsider-authored free text such as commit subjects and release/tag metadata.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata