moai-essentials-refactor

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly shows runtime calls to Context7Client.get_library_docs (e.g., fetching "/refactoring-guru" and Context7 library docs) and then uses those external Context7/Refactoring.Guru patterns to drive analysis and refactoring decisions, which means it ingests public third‑party documentation that can materially influence tool actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 01:07 AM