helm-chart-scaffolding
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly instructs fetching and rendering public, untrusted charts (e.g., Chart.yaml lists repositories like https://charts.bitnami.com/bitnami and the documentation/scripts call "helm dependency update", "helm repo add ...", "helm template" and "helm install"), so the agent would download and parse third-party chart/templates as part of validation and could therefore be exposed to injected content.
Audit Metadata