turso-db

Warn

Audited by Snyk on Mar 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's sync documentation (references/sync.md and the SDK examples) instructs the agent to connect to and pull/bootstrap data from remote Turso Cloud endpoints (e.g., libsql://your-db.turso.io or https://your-db.turso.io), which ingests untrusted third‑party database content that the agent is expected to read and act on (refresh UI, run follow-up logic), so remote content could materially influence tool behavior and enable indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 27, 2026, 10:49 AM
Issues
1