homelab-deployment
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's service-validator subagent (via ~/.claude/skills/homelab-deployment/scripts/verify-deployment.sh and the "External Routing" checks) explicitly fetches and inspects an external service URL (e.g., https://jellyfin.patriark.org) for TLS, headers, and response, meaning the agent will read arbitrary public HTTP responses provided by third parties.
Audit Metadata