opt-datagrid-install

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly fetches package metadata (npm view ... --registry=...) and installs/reads third‑party package docs from node_modules (e.g., node_modules/@reopt-ai/opt-datagrid/dist/docs/04-migration/ and related in-package docs) and then uses that content during breaking-change detection and migration planning to decide and apply code edits, so external package content can materially influence the agent's actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 07:22 AM
Issues
1
Security Audit — snyk — opt-datagrid-install