nexus-room
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md describes runtime intake from the internal kanban
#nexuschannel via command/history reads (e.g.,kanban channel history nexus -n 50) and exchanging “chunky summary updates,” which is outsider-submitted free text if external users can post into that channel.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs agents to call the wiki API at https://nexus.langwatch.ai (using NEXUS_PROD_URL + NEXUS_PROD_AGENT_TOKEN) and to "Read the writing-rules wiki page in full before drafting," which means runtime-fetched content from that URL will directly control the agent's instructions.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata