create-seed-skill

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly instructs agents to call real web-search and content-extraction APIs (You.com / "Search the web..." queries) — see SKILL.md, assets/example-SKILL.md, assets/example-path-a.ts, the test files, and the prompts.jsonl entries — which ingest and rely on untrusted third-party web content as part of the workflow, enabling indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 02:44 AM