threads-blog-post
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Fetcher agent (described in SKILL.md and implemented in scripts/fetch_threads.py) explicitly crawls user-provided Threads.net/Threads.com URLs using agent-browser to extract post text, Open Graph/JSON-LD metadata and media (user-generated, untrusted third-party content) which is then consumed by the Content and Media agents to drive generation of blog posts and downloads—allowing that third‑party content to directly influence agent decisions and outputs.
Audit Metadata