nix
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill’s workflow and examples explicitly fetch and process content from arbitrary public URLs and repositories (e.g., nix-prefetch-url https://example.com/source.tar.gz, fetchFromGitHub/fetchurl, and the curl example), so the agent can download and evaluate untrusted, user-hosted third‑party content as part of builds.
Audit Metadata