moai-foundation-claude

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's documentation and required workflows explicitly instruct the agent to add and install plugin marketplaces and plugins from external GitHub/HTTP URLs (see reference/claude-code-discover-plugins-official.md showing "/plugin marketplace add" and "/plugin install https://github.com/...") and to enable browser/WebFetch browsing (--chrome / WebFetch/WebSearch in the CLI and headless docs), which causes the agent to fetch and interpret untrusted public third-party content that can change tool behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 07:53 PM