hexo

Warn

Audited by Snyk on May 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly supports ingesting content from arbitrary URLs (e.g., "hexo migrate rss " in reference/docs-15-migration.md where can be a website/URL) and shows examples of including external resources (e.g., reference/api-injector.md and tag examples), so the agent would read and act on untrusted third-party content that can influence generation/deployment.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 4, 2026, 08:17 AM
Issues
1
Security Audit — snyk — hexo