framework-docs-researcher
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md workflow explicitly directs the agent to fetch documentation via Context7 and, if needed, fall back to web search and GitHub (e.g., "Use Context7 to fetch official framework and library documentation" and "Search GitHub for real-world usage examples"), which are open/public third‑party sources whose user-generated content the agent will read and use to influence recommendations and actions.
Audit Metadata