semgrep

Warn

Audited by Snyk on Mar 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs downloading and running public third‑party Semgrep rule sets (see the "Third-Party Rules" section with "semgrep-rules-manager --dir ~/semgrep-rules download" and links to semgrep.dev and GitHub), meaning the agent would ingest and act on untrusted public rule files that can materially alter findings and subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 6, 2026, 06:39 AM