search-for-service
Warn
Audited by Snyk on Apr 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's SKILL.md instructs the agent to search and browse the public "x402 bazaar" marketplace and to probe arbitrary endpoints using commands like
npx agnic@latest x402 bazaar search/listandx402 details <url>, which fetch and interpret untrusted third-party listings and arbitrary URLs as part of its workflow, so those external contents could inject instructions that influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata