alterlab-trdizin
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The skill calls the outsider-authored public TR Dizin Elasticsearch API at runtime (
https://search.trdizin.gov.tr/api/defaultSearch/{type}/...), ingests the returned JSON_sourcefields (includingjournalYear/rejectYearList) into the agent’s context, which is indirect prompt injection exposure from a third-party free-text source.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata