alterlab-research-pipeline
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's integrity_verification_agent (agents/integrity_verification_agent.md) and the pipeline SKILL.md explicitly require WebSearch/DOI lookups and citation/source tracing (Google Scholar, publisher pages, PubMed, etc.) to verify references and claims in Stage 2.5 and Stage 4.5, which means the agents fetch and interpret untrusted public web content that can directly change PASS/FAIL decisions and pipeline actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata