mcp-server-chart

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). SKILL.md explicitly states in the generate_path_map and generate_pin_map tool descriptions that the tool "will use these keywords to search for specific POIs and query their detailed data, such as latitude and longitude, location photos, etc.," which indicates the agent fetches and ingests public third-party POI data/media that can influence mapping and marker behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 08:45 AM
Security Audit — snyk — mcp-server-chart