logs-nextjs
Warn
Audited by Snyk on Mar 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's docs explicitly enable an MCP-enabled agent to query project logs (references/debug-logs-mcp.md) and the session-linking examples show logging frontend user messages (references/link-session-replay.md, e.g., the /api/chat examples), so the agent is expected to read untrusted user-generated log/session content that could influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata