threads-blog-post

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Fetcher agent (described in SKILL.md and implemented in scripts/fetch_threads.py) explicitly crawls user-provided Threads.net/Threads.com URLs using agent-browser to extract post text, Open Graph/JSON-LD metadata and media (user-generated, untrusted third-party content) which is then consumed by the Content and Media agents to drive generation of blog posts and downloads—allowing that third‑party content to directly influence agent decisions and outputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 02:07 AM