compute-plugin-package-overlay-cve-list
Fail
Audited by Snyk on Jul 31, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The list contains placeholder/untrusted hosts and GitHub paths using an unknown username or unexpanded template variables (e.g., domain "x", user "x", and "${OVERLAYS_GH}" interpolation) which obscure the true destination and can be used to host arbitrary or malicious payloads, while the other entries (redhat.atlassian.net and the redhat-developer repo) are official.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required runtime path reads insider PR/issue free text from GitHub via
fetchPr()/gh pr view --json number,title,body,urland then parsespr.title/pr.bodyinparsePrBodyAssociations()andjirasFromCommit().
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata