contract-testing
Warn
Audited by Snyk on Apr 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). This skill explicitly integrates with arbitrary Pact Broker URLs (see SKILL.md "Pact Broker Integration" and references/agent-commands.md's withBroker/brokerUrl and webhook examples), meaning the agent will fetch and ingest third‑party Pact files from external broker endpoints and use them (e.g., can-i-deploy / verification results) to make deployment/semver decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata