auth0-nextjs
Warn
Audited by Snyk on Apr 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's Setup Guide (references/setup.md) includes an automated setup script that curls a public GitHub install script (curl ... raw.githubusercontent.com | sh) and runs the Auth0 CLI to fetch tenant/app JSON which is parsed and written into .env files, meaning it explicitly fetches and ingests public third‑party content whose outputs are parsed and used to drive further actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata