moai-essentials-debug

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md shows repeated runtime calls to Context7 (e.g., context7.get_library_docs with library IDs like "/microsoft/debugpy" and "/plasma-umass/scalene") and explicitly uses those fetched community/third‑party documents to drive pattern matching, recommended fixes, and automated debugging actions, so untrusted external content can materially influence agent decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 05:15 PM