nmap-scan-management

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The SKILL.md explicitly exposes the agent to untrusted third-party content because tools like nmap_get_scan return the "full scan result as originally captured" (see "Scan History" / "Retrieve a Specific Scan") and the workflow instructs the agent to retrieve and compare those external host/service results, which the agent is expected to read and could materially influence subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 02:40 PM