claudeception
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's Step 2 ("Research Best Practices") in SKILL.md and the README explicitly instruct the agent to search the open web, incorporate findings, and add "References" with source URLs, so the agent is expected to fetch and interpret untrusted public web content that can influence extracted-skill creation and subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata