sui-seal

Warn

Audited by Snyk on May 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's SealClient setup explicitly instructs the SDK to fetch /v1/service from configured key servers when verifyKeyServers: true (SKILL.md, "SealClient setup"), and those key-server endpoints are permissionless/untrusted and their responses are parsed/used by the client (and by fetchKeys/decrypt flows) to decide whether to release decryption keys, so untrusted third-party content can materially influence behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 7, 2026, 10:54 AM
Issues
1
Security Audit — snyk — sui-seal