blocking-muting-management

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's scripts explicitly scan and parse public, user-generated content on x.com (e.g., src/blockBots.js reads your followers page at x.com/USERNAME/followers and src/muteByKeywords.js scans the timeline/search results) and then uses that untrusted content to decide and perform actions (block/mute), which enables indirect prompt-injection style influence.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 09:53 AM