bun-publish-setup
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs running and interpreting public npm registry/web queries (e.g., "npm view " and visiting "https://www.npmjs.com/package//access") so the agent will fetch and act on untrusted, user-published npm package pages/metadata as part of its workflow.
Audit Metadata