plan-trip
Warn
Audited by Snyk on Jun 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The workflow explicitly runs “cash search in parallel via duffel, ignav, google-flights, and the relevant free MCPs (Skiplagged, Kiwi)” and “award search in parallel via seats-aero,” which commonly ingest third-party web/free-form listing content at runtime (outsider-authored public marketplace/search results) into the agent’s LLM context for ranking and math.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata