blocking-muting-management
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's scripts explicitly scan and parse public, user-generated content on x.com (e.g., src/blockBots.js reads your followers page at x.com/USERNAME/followers and src/muteByKeywords.js scans the timeline/search results) and then uses that untrusted content to decide and perform actions (block/mute), which enables indirect prompt-injection style influence.
Audit Metadata