claude-code-plugin

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly installs and updates plugins from public sources (e.g., /plugin install github:owner/repo, marketplace add owner/repo, and curl to raw.githubusercontent.com to fetch .claude-plugin/plugin.json and marketplace.json), which causes the agent to fetch and interpret untrusted, user-provided content from the open web (GitHub/marketplaces).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:49 AM