obsidian-plugin-shadcn-ui
Warn
Audited by Snyk on Apr 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's CLI workflow explicitly fetches and inspects external registry items and arbitrary URLs (see references/cli.md: "
addaccepts URLs" and "docs... Fetch the URLs to get the actual content" and guidance to use--view/--diffto review third-party registry code), so the agent will read untrusted public/web content that can influence installation/merge actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata