update-swiftui-apis
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's Workflow (SKILL.md step 3) directly instructs the agent to call Sosumi MCP methods like searchAppleDocumentation and fetchAppleDocumentation and the tool list includes fetchExternalDocumentation (full https URLs) to retrieve public Apple docs, WWDC transcripts, and external web pages which the agent must read and act on to determine API replacements and open PRs, exposing it to untrusted third‑party web content that can influence behavior.
Audit Metadata