sandbox-npm-install

Warn

Audited by Snyk on Sep 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The required workflow executes an installation script that copies local package configurations and runs npm install, which downloads packages from public or private npm registries containing arbitrary code and package metadata. However, community registries are evaluated as low risk because the agent must actively select or specify packages to install rather than having outsider text automatically injected into a monitored feed.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 07:28 AM
Issues
1
Security Audit — snyk — sandbox-npm-install