cutile-python

Warn

Audited by Snyk on May 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's mandatory workflow (Step 0 "Search Examples" in SKILL.md and the orchestration docs like examples/tilegym_and_examples_guide.md and orchestration/*.md) explicitly requires cloning/reading public third-party sources (e.g., https://github.com/NVIDIA/TileGym.git, the cuTile spec at https://docs.nvidia.com/cuda/cutile-python, and a cached PyTorch source) and instructs agents to read and base decomposition/code-generation decisions on that untrusted, user-generated web content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 02:14 AM
Issues
1
Security Audit — snyk — cutile-python