literature-search
Warn
Audited by Snyk on Apr 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's Mandatory Search Protocol explicitly requires making real API calls to public third-party sources (Semantic Scholar, OpenAlex, arXiv, PubMed, CrossRef) and parsing returned abstracts/TLDRs and metadata (see "Step 1: Semantic Scholar Search" and "Step 2: OpenAlex Search"), which the agent must read and use to rank/select papers and drive citation-chaining, exposing it to untrusted third-party content that could carry indirect prompt-injection payloads.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata