helm-chart-scaffolding

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly instructs fetching and rendering public, untrusted charts (e.g., Chart.yaml lists repositories like https://charts.bitnami.com/bitnami and the documentation/scripts call "helm dependency update", "helm repo add ...", "helm template" and "helm install"), so the agent would download and parse third-party chart/templates as part of validation and could therefore be exposed to injected content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 03:58 PM