claude-code

Warn

Audited by Snyk on Mar 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill's SKILL.md and docs explicitly instruct the agent to fetch and read external URLs (e.g., "Fetch the complete documentation index at: https://code.claude.com/docs/llms.txt" in docs/agent-teams.md), to use the plugin marketplace and install community plugins, and to connect MCP servers (Notion, Figma, databases) so the agent will ingest and act on open/public third‑party content that can change tool availability and drive follow-up actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 15, 2026, 04:45 PM
Issues
1