lead-enrichment
Warn
Audited by Snyk on Jul 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes—
scripts/find.pyandscripts/enrich.pycall the webclaw API (/v1/extractand/v1/search) on runtime-provided listing/company URLs, and the extracted page text (outsider-authored public web content) is returned and then used to populate the agent’s LLM context via the tool results.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata