autoresearch
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow includes “Search literature” via web-based tools (e.g.,
web_search_exa/ arXiv / CrossRef) and then “Save everything toliterature/”; any fetched public web pages or scraped content would be outsider-authored free text ingested into the agent’s LLM context through the literature-search/scraping path.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata