framework-docs-researcher

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md workflow explicitly directs the agent to fetch documentation via Context7 and, if needed, fall back to web search and GitHub (e.g., "Use Context7 to fetch official framework and library documentation" and "Search GitHub for real-world usage examples"), which are open/public third‑party sources whose user-generated content the agent will read and use to influence recommendations and actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 11:52 AM