bundle-social-platform-ops
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow (SKILL.md and references/09-misc.md) instructs the agent to call Bundle.social endpoints that import or return user-generated public content—e.g.,
GET /api/v1/misc/reddit/post-requirementsandGET/POST /api/v1/misc/google-business/reviewsand Facebook recommendations import—which means the agent will ingest and act on untrusted third-party social media/forum/review content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata