datagouv-mcp-server

Warn

Audited by Snyk on May 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill connects to the public MCP server at https://mcp.data.gouv.fr/mcp and exposes tools (search_datasets, get_dataset, list_resources, get_resource) that fetch and have the agent read public data.gouv.fr datasets/resources (third‑party public content) which the agent uses to drive exploration and responses, enabling indirect prompt injection risk.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 10:05 AM
Issues
1
Security Audit — snyk — datagouv-mcp-server