lead-research-assistant

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The skill’s runtime workflow instructs the agent to “Search for companies matching the criteria” and to “look for signals of need (job postings, tech stack, recent news)”, which implies ingesting outsider-authored free text from external sources (e.g., public web/job/news content) during lead research.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 04:52 PM
Issues
1
Security Audit — snyk — lead-research-assistant