crxhub-cli
Warn
Audited by Snyk on Mar 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly retrieves and installs extension assets from public GitHub Releases (see SKILL.md: "Manage browser extensions from GitHub Releases" and commands like "$CRX install <owner/repo>" / "$CRX update <owner/repo>"), i.e., arbitrary user-generated third-party content that the tool must inspect and act on, so untrusted release assets/metadata could materially influence tool behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata