grep-build-app
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md routes the user’s refined prompt (outsider-authored free text) into the
app-builderexpert vianode "$SCRIPTS_DIR/grep-api.js" run "<refined_prompt>" --expert-id=app-builder --effort=build, so the workflow ingests user text at runtime to generate an HTML/JS app.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata