pub-package-explorer

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflow explicitly uses dart pub unpack (and reads package source from .dart_tool/package_config.json or the pub cache) to download and inspect packages from pub.dev or other public package sources, which are untrusted third-party, user-published code and files that the agent is instructed to read and act on.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 04:03 AM