configure-formatting
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md "Version Checking" step explicitly instructs the agent to verify latest releases via WebSearch/WebFetch of public sites (e.g., biomejs.dev, GitHub releases, prettier.io, npm, docs.astral.sh, releases.rs), requiring the agent to fetch and interpret open third-party webpages whose content could influence update/configuration actions.
Audit Metadata