legacy-to-ai-ready

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly includes a "resource-scout" component (assets/resource-scout/SKILL.md) that instructs the agent to web-search and browse public marketplaces and GitHub (SkillsMP, SkillHub.club, claudeskills.info, various GitHub repos) and a "skill-downloader" (assets/skill-downloader/SKILL.md) that downloads and validates SKILL.md and archives from arbitrary GitHub URLs and direct URLs—i.e., the agent is expected to fetch and read untrusted, user-generated third‑party content as part of its workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:25 PM