alterlab-vcd-infographic
Warn
Audited by Snyk on Apr 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow in SKILL.md (Data Assessment & Story Discovery and Agentic Protocol) explicitly instructs the agent to "Search the web" for contextual benchmarks and exemplary visualizations, meaning it will fetch and read arbitrary public web content that can influence its design decisions and subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata