nango-function-builder
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly requires inspecting provider API docs and sample payloads and makes runtime calls to third-party endpoints via nango.get/nango.paginate (see the "Workflow" and "Sync Strategy Gate" in SKILL.md and the patterns in references/syncs.md), so it ingests untrusted external API/docs content that directly influences checkpointing, pagination, and other execution decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata