prompt-architect
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's mandatory Phase 2 ("Execution (MANDATORY)" in SKILL.md) and the referenced research guide (references/research-guide.md) require using a research/researcher tool and web search to fetch and integrate content from public sources (e.g., GitHub, X/Twitter, blogs, arbitrary web pages), so untrusted third‑party content is read and used to shape prompts—exposing the agent to indirect prompt injection risk.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's mandatory Phase 2 research requires fetching external prompt architectures from GitHub repositories and Gists (e.g., GitHub repos like https://github.com/.../system-prompts-and-models-of-ai-tools, https://github.com/.../leaked-system-prompts, https://github.com/.../awesome-system-prompts and gist.github.com / pastebin), and those fetched prompt files would directly feed and control the agent's prompts, making them a required runtime dependency.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata