nzb-search
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill's scripts (scripts/nzb-api.sh) and SKILL.md explicitly fetch and normalize search results from public Newznab indexers (e.g., https://scenenzbs.com/api, https://api.nzbgeek.info, https://nzbfinder.ws, https://api.nzbplanet.net) via curl, then parse, filter, sort, and act on that untrusted third-party content (search_all, search, download, cartadd), so external user-generated results can directly influence tool actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata