effect-dependency-injection
Warn
Audited by Snyk on Feb 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's HttpClientLive implementation explicitly calls fetch(
${config.apiUrl}${url}) (in Layer.effect) and UserServiceLive parses response.json(), so at runtime it can ingest and interpret arbitrary content from whatever external apiUrl is configured (open/public third-party endpoints).
Audit Metadata