open-websearch-maintainer
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's required validation and live-check workflow (references/validation.md and SKILL.md) explicitly instruct running live tests like
npm run test:web-content:live,test:bing:live, andtest:article-fetch:live, which fetch and parse public web pages (search engines/articles) — untrusted third-party content the agent must read/interpret and that can materially influence parsing and tool behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata