website-audit

Warn

Audited by Snyk on Apr 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md Phase 2 "Full Site Crawl" requires the agent to fetch and "read every word" of a user-provided website and follow internal links, meaning it ingests arbitrary public/untrusted web content (the provided URL and linked pages) that directly influences audit decisions and actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 18, 2026, 09:04 PM
Issues
1
Security Audit — snyk — website-audit