kmp-shadcn-compose
Warn
Audited by Snyk on Aug 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill instructs the agent to fetch documentation and component signatures from GitHub (
github.com/ronjunevaldoz/shadcn-compose) and Maven Central, which represents actively fetched, trusted or developer-controlled content without an untrusted outsider submission feedback loop.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata