nyc-hpd
Warn
Audited by Snyk on Apr 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The SKILL.md workflow explicitly instructs the agent to fetch and ingest open/public Socrata datasets from data.cityofnewyork.us (PLUTO
64uk-42ksand HPD datasetswvxf-dwi5,csn4-vhvf,ygpa-z7cr,tesw-yqqrin Steps 2–3), which includes public complaint/description text that the agent reads and uses to make decisions (e.g., flagging hazards), so untrusted third‑party content could influence behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata