offsite-signal-analyzer
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
backlinksmode the required workflow ingests “backlink/referring-domain exports” and “pasted CSV” from the user (outsider-authored text) without requiring the agent to first select a specific trusted item, and the skill explicitly treats fetched/pasted log/backlink content as untrusted input at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata