skill-writing
Warn
Audited by Snyk on Sep 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow fetches documentation and specs from external URLs like agentskills.io and code.claude.com via
WebFetchandcurl, which are active search/fetch actions rather than unprompted monitoring feeds.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata