skill-creator

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to download and index upstream documentation via the "Auto-Updating Documentation Pattern" (e.g., /plugin-creator:add-doc-updater that collects a source URL) and to run dynamic context-injection commands (e.g., !gh pr view $0 --json ...) which cause the agent to ingest untrusted public third-party content (public docs, PRs) that can materially influence subsequent tool use and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 08:43 AM
Issues
1