secrets-management
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow reads repository-targeted files and searches for secret-adjacent content using Grep/Glob (e.g., .env files, config files, and Git-related files), so an outsider can supply poison via text that gets ingested as part of the repo/code/config scan.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata