dependency-analyzer
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs running tools like npm audit, npm outdated, and npx bundle-phobia-cli (and uses npm/npx commands throughout the references) which fetch and analyze packages and metadata from public registries (npm, bundlephobia) so the agent ingests untrusted third-party package content/metadata that can influence its actions.
Audit Metadata