skills/openaec-foundation/blender-bonsai-ifcopenshell-sverchok-claude-skill-package/blender-syntax-addons/Snyk
blender-syntax-addons
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill includes a concrete runtime example (references/examples.md, "Example 4: Extension with Bundled Wheels and Network Access") whose init.py operator performs requests.get(prefs.api_url) to download and save arbitrary remote API responses (user-configurable URL), which ingests untrusted third-party content into the add-on workflow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata