research
Warn
Audited by Snyk on May 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's fallback workflow explicitly requires and uses WebSearch + WebFetch to fetch and read public third‑party pages (see SKILL.md Phase 3b: Step 2 "Source Selection" and Step 4 "Read + Extract", plus the Dependencies section that names WebSearch/WebFetch and optional Reddit/HN/ scholar.google.com), and it synthesizes those untrusted, user‑generated or public-web sources into decisions and outputs—making indirect prompt injection possible.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata