analyzing-tls-certificate-transparency-logs

Warn

Audited by Snyk on Mar 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill directly queries public Certificate Transparency sources (e.g., crt.sh via the search_crtsh_api function in scripts/agent.py and pycrtsh calls shown in SKILL.md, and optionally certstream in references) and ingests untrusted, public domain/certificate data which the agent parses and uses to drive detection and reporting decisions, so crafted third‑party inputs could influence its actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 15, 2026, 03:56 PM
Issues
1