nemoclaw-security-best

Warn

Audited by Snyk on Apr 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's network policy and presets (see "Policy Presets" and "Operator Approval Flow" in SKILL.md / references/best-practices.md) explicitly allow the agent to fetch content from public endpoints like CDNs, npm/PyPI registries, Docker Hub, Hugging Face, Discord CDN, and arbitrary approved URLs, meaning untrusted user-generated third-party content can be retrieved and materially influence the agent's behavior (e.g., by installing packages, downloading models, or executing fetched artifacts).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 7, 2026, 04:30 AM
Issues
1