personal-shopper
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text is ingested when the skill’s search-layer agents use runtime web tools (
web_search,web_fetch,browser,camofox, Exa) to fetch and extract review/forum/news page content authored by third parties, which is then summarized and passed through the agent pipeline into the LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata