tweet-ideas
Warn
Audited by Snyk on Feb 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill fetches trending titles from third-party news/social feeds (see fetchTrendsFromNews in index.ts which imports createNewsFeed from ../../../feeds/news and the SKILL.md "Trend Mode" description), and it injects those untrusted feed items directly into the prompts used to generate tweets, so external content can materially influence the agent's outputs.
Audit Metadata