meta-repo
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly instructs the agent to run meta git clone / meta git update (cloning arbitrary git URLs from .meta) and meta exec (running commands across child repos) and to install third‑party meta- packages, which means the agent will fetch and execute untrusted, user-generated repositories/plugins from public sources (e.g., GitHub) that can indirectly inject instructions affecting subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata