code-security-audit

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to fetch and read external web API documentation (up-to-date SKILL.md and references/doc-urls.md using fetch_webpage) and to load and analyze PR diffs/public repository content (code-security-audit SKILL.md, assets/security-review-command.md, and the evals run_eval owner/repo#123 flow), which are untrusted, user-generated third‑party sources that the agent parses and uses to drive analysis and PR comments.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 10:10 AM