hypogenic
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's SKILL.md explicitly instructs fetching and ingesting public third-party content — e.g., cloning GitHub datasets (git clone https://github.com/...) and preprocessing research PDFs placed in literature/YOUR_TASK_NAME/raw/ with GROBID/pdf_preprocess.py (and examples mentioning social-media posts as data) — and uses that untrusted content to generate and refine hypotheses that directly influence subsequent agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata