mcp-builder
Warn
Audited by Snyk on Sep 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The evaluation harness script (
scripts/evaluation.py) reads tasks and questions from an arbitrary external XML file (eval_file), which represents outsider-authored free text ingested by the agent loop during evaluation runs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata