namer
Warn
Audited by Snyk on Apr 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and parses public third-party content (see SKILL.md and references/platform-checks.md) and the runtime checker script scripts/check.py calls RDAP and public APIs and brave_web_search (e.g., rdap.verisign, GitHub API, npm, PyPI, crates.io, Reddit, Bluesky and general web search), and those external results are read and fed into availability checks, scoring, and automated next-step recommendations—so untrusted web content can materially influence agent decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata