ai-engineering
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's agentic-system-design reference (references/agentic-system-design.md) defines a "search_web" tool and shows tool_use_agent/ReAct pseudocode where the agent calls web/search tools and ingests their observations into the reasoning loop, meaning open web (untrusted) content is fetched and can directly influence subsequent actions and tool use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata