skill-supply-chain-audit
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow runs a static scanner that directly reads and parses text files inside an outsider-supplied target skill package directory (e.g., SKILL.md and other .md/.py/.js/etc files) via
scripts/audit_skill.py→scan()→entry.read_bytes()/parse_frontmatter()and therefore could ingest arbitrary attacker-authored free text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata