tech-stack-evaluator

Warn

Audited by Snyk on Apr 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow and scripts (SKILL.md: "ecosystem_analyzer.py" and the rule "Never assess ecosystem health without checking GitHub activity, download trends, and community support") explicitly require fetching and interpreting public third‑party data (GitHub, npm, community metrics), which the agent would read and use to drive recommendations, creating a clear avenue for indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 5, 2026, 08:07 PM
Issues
1
Security Audit — snyk — tech-stack-evaluator