skill-manager

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill manager fetches and installs skills directly from public GitHub repositories (see scripts/install.py which downloads or clones github.com repos and SKILL.md files) and its SKILL.md explicitly instructs to "browse the repo" and "read their SKILL.md for details", meaning untrusted, user-generated content is loaded and used to decide installs/syncs and trigger behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 10:06 AM