vibeteam-readiness
Warn
Audited by Snyk on Jun 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s runtime workflow uses
curlto fetch health endpoints and other API responses (e.g., Sentry unresolved issues, Langfuse traces, GitHub issue title) and then pipes the returned JSON intojq, which becomes readable text in the agent’s context; these responses are outsider-authored content from third-party/public services.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata