nmap-scan-management
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The SKILL.md explicitly exposes the agent to untrusted third-party content because tools like nmap_get_scan return the "full scan result as originally captured" (see "Scan History" / "Retrieve a Specific Scan") and the workflow instructs the agent to retrieve and compare those external host/service results, which the agent is expected to read and could materially influence subsequent actions.
Audit Metadata