bun-publish-setup

Warn

Audited by Snyk on Mar 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs running and interpreting public npm registry/web queries (e.g., "npm view " and visiting "https://www.npmjs.com/package//access") so the agent will fetch and act on untrusted, user-published npm package pages/metadata as part of its workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 03:47 AM