GraphQL Schema Drift Detector

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly states the skill uses the GraphQL introspection query (__schema) to fetch live schema definitions from running GraphQL endpoints and integrates with external schema registries like Apollo Studio and Hasura, meaning it ingests untrusted third-party schema content that the agent reads and uses to drive diffs, reports, and notifications.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:36 AM
Issues
1