aspire
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly instructs the agent to fetch and read public documentation and community content via MCP doc tools (list_docs / search_docs / get_doc) and fallbacks (Context7 library queries and GitHub search) that pull from aspire.dev, CommunityToolkit/Aspire and other public GitHub repos, so the agent will ingest untrusted user-generated third‑party content as part of its workflow.
Audit Metadata