nzb-search

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). This skill's scripts (scripts/nzb-api.sh) and SKILL.md explicitly fetch and normalize search results from public Newznab indexers (e.g., https://scenenzbs.com/api, https://api.nzbgeek.info, https://nzbfinder.ws, https://api.nzbplanet.net) via curl, then parse, filter, sort, and act on that untrusted third-party content (search_all, search, download, cartadd), so external user-generated results can directly influence tool actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 07:14 AM
Issues
1