health-check
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md shows the tool runs health.sh which uses curl to fetch arbitrary HTTP/HTTPS URLs (e.g., "health.sh https://api.example.com/health" and "--file urls.txt") and inspects response bodies/JSON, meaning it ingests untrusted public web content that can materially influence checks and subsequent decisions.
Audit Metadata