publish-repo
Warn
Audited by Snyk on Jul 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). SKILL.md’s required workflow runs
npx skills add . --listandnpx skills add <owner>/<repo> --skill '*' ...which causes the agent to ingest free-form skill metadata/README/frontmatter from the target repository’sskills/contents (outsider-authored repo files) into the LLM context via the skills tooling during discovery/verification.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata