zotero-cli

Warn

Audited by Snyk on May 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflows (e.g., "zot add --url", "zot --json pdf", "zot update-status" using the Semantic Scholar API, and "zot workspace query" with PDF fulltext / exported JSON pasted into Claude Code) explicitly fetch and index public third-party content such as arXiv/DOI-resolved papers and Semantic Scholar results and then feed that untrusted content into RAG/query workflows, so external content can influence the agent's decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 10:39 AM
Issues
1
Security Audit — snyk — zotero-cli