Feature-Based-Layered-Architecture

Warn

Audited by Snyk on Feb 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The SKILL.md "How to Use" section explicitly instructs running npx skills add with public GitHub URLs (e.g., https://github.com/supabase/agent-skills), which fetches and installs third‑party, user‑authored skill code from the open web that can alter agent behavior and thus could enable indirect injection of instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 25, 2026, 04:19 AM