npm-research
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches package data from public npm-related sources (e.g.,
search/package_infofrom the npm registry,bundle_sizevia Bundlephobia, andvulnerabilitieschecking npm audit advisories) and the workflow requires the agent to read and act on those results to make recommendations, so untrusted README/advisory content could influence behavior.
Audit Metadata