NYC

hono-routing

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's templates and scripts explicitly fetch external, third-party content (e.g., templates/error-handling.ts uses fetch('https://api.example.com/data') and scripts/check-versions.sh runs npm view … against the public npm registry), so the runtime can ingest untrusted public web data that the agent may read/interpret.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:05 PM