configure-formatting

Warn

Audited by Snyk on Mar 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md "Version Checking" step explicitly instructs the agent to verify latest releases via WebSearch/WebFetch of public sites (e.g., biomejs.dev, GitHub releases, prettier.io, npm, docs.astral.sh, releases.rs), requiring the agent to fetch and interpret open third-party webpages whose content could influence update/configuration actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 6, 2026, 09:33 AM