alliance-ml

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's workflow explicitly instructs downloading and loading models and datasets from public HuggingFace (e.g., "huggingface-cli download", git clone https://huggingface.co/..., and load_dataset examples in references/huggingface.md and vllm.md), which are untrusted/user-contributed third‑party resources that the agent/user is expected to load and run (thus able to influence tool decisions and subsequent actions).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 06:11 PM
Issues
1