effect-deep-audit
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to clone and grep public repositories (e.g., "git clone https://github.com/Effect-TS/effect") and to consult effect-mcp / effect.website, so it will fetch and interpret untrusted public third-party source/docs that can materially influence audit decisions and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata