alterlab-yok-tez

Warn

Audited by Snyk on Jun 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The required runtime workflow uses the saidsurucu/yoktez-mcp connector to call search_yok_tez_detailed, which ingests readable thesis metadata/abstract text from the public YÖK Ulusal Tez Merkezi records (outsider-authored theses) into the agent’s LLM context.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). This skill relies at runtime on an external hosted MCP connector (https://yoktezmcp.fastmcp.app/mcp) — and documents the companion GitHub package (https://github.com/saidsurucu/yoktez-mcp) — which the agent calls to execute remote tools (search_yok_tez_detailed / get_yok_tez_document_markdown), so remote code/tool execution is a required runtime dependency.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 03:28 PM
Issues
2
Security Audit — snyk — alterlab-yok-tez