hashimoto-cli-ux

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill clearly fetches and uses a remote skill index (e.g., load_manifest()/check_manifest_age() and reqwest::blocking::get(MANIFEST_URL) in cmd_doctor and the documented "Update" command), meaning untrusted third-party manifest/content would be read and can influence which skills are listed/installed and subsequent tool actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 07:23 PM