skill-optimizer
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md and references/documentation-scraping.md (and scripts/scrape_documentation_helper.py) explicitly instruct using Skill_Seekers to scrape public documentation and copy those scraped reference files into the skill's references/ directory, which Claude will read on demand as part of its workflow—so arbitrary third‑party web content is fetched and ingested and can influence tool use and decisions.
Audit Metadata