typefully
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill routinely calls the Typefully API (e.g., GET /social-sets and GET /social-sets/{id}/drafts in scripts/typefully.js) and ingests user-generated draft/post and platform data which the CLI uses to choose target platforms and build/update/publish drafts, so untrusted third-party content can materially influence actions.
Audit Metadata