implementing-logging
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's AI analysis guide (references/AI-ANALYSIS.md) includes runtime code that calls transformers.from_pretrained (e.g., BertTokenizer.from_pretrained('bert-base-uncased')) and similar networked install/curl commands, which fetch public third-party model/data from the open web and then have the agent read and act on those outputs to influence analysis and decisions.
Audit Metadata