data_analysis
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill runtime ingests user-provided dataset content by loading arbitrary local files (e.g., via
pl.read_csv/pl.read_json/pl.read_ndjson/pl.read_parquetor passing--file_path), then uses the parsed strings/numeric fields when generating reports and formatted output.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata