download-docs
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly downloads documentation from public GitHub repos or arbitrary URLs as specified in vault/configs/{config_name}.json (Step 3: download_from_github / download_from_urls) and then reads and interprets the first 20–30 lines of each file to decide filtering and deletion (Step 5), so untrusted third‑party content can directly influence agent actions.
Audit Metadata