sysml-v2-guide-validator
Warn
Audited by Snyk on Feb 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill includes an explicit runtime-refresh flow (scripts/setup_official_validator.sh) and a default remote source (https://github.com/LnYo-Cly/sysmlv2-validator) referenced in SKILL.md and references/sources.md, so it can fetch and build untrusted public GitHub content that would be executed as the official validator and thus could materially change tool behavior.
Audit Metadata