opentui-doc
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill documentation explicitly instructs runtime loading of untrusted external content (e.g., references/tree-sitter.md shows adding Tree-sitter parsers via public GitHub/raw URLs for WASM and query files, and references/plugin-slots.md shows dynamic runtime imports of external plugins), so the agent/app would fetch and execute third‑party resources that can materially change behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata