alterlab-lamindb

Warn

Audited by Snyk on Apr 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to fetch and ingest open/public third‑party content (e.g., arbitrary HTTP/HTTPS artifacts and REST APIs in references/integrations.md "HTTP/HTTPS (Read-Only)" and "REST API Integration", HuggingFace datasets in references/integrations.md, and public ontology lookup/import via bionty like bt.CellType.import_source() and curator.cat.lookup(public=True) in references/ontologies.md and references/annotation-validation.md), and that external content is used to standardize/validate data and drive subsequent curation, annotation, and pipeline actions—so untrusted web/third‑party data can materially influence tool use and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 12:46 AM
Issues
1
Security Audit — snyk — alterlab-lamindb