lead-research-assistant
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill’s runtime workflow instructs the agent to “Search for companies matching the criteria” and to “look for signals of need (job postings, tech stack, recent news)”, which implies ingesting outsider-authored free text from external sources (e.g., public web/job/news content) during lead research.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata