dependency-analyzer

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs running tools like npm audit, npm outdated, and npx bundle-phobia-cli (and uses npm/npx commands throughout the references) which fetch and analyze packages and metadata from public registries (npm, bundlephobia) so the agent ingests untrusted third-party package content/metadata that can influence its actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 05:51 AM