api-design-reviewer
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill runtime path reads a user-provided OpenAPI/raw JSON file at
scripts/api_linter.py/api_scorecard.py/breaking_change_detector.pyviaopen(args.input_file/spec_file)andjson.load(...), so outsider-authored text can be supplied directly as input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata