AGENT LAB: SKILLS

aspire

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly instructs the agent to fetch and read public documentation and community content via MCP doc tools (list_docs / search_docs / get_doc) and fallbacks (Context7 library queries and GitHub search) that pull from aspire.dev, CommunityToolkit/Aspire and other public GitHub repos, so the agent will ingest untrusted user-generated third‑party content as part of its workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:41 PM