gathering-competitive-intelligence
Warn
Audited by Snyk on Apr 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly instructs ingesting and acting on public, untrusted third-party sources (e.g., "Primary: Competitor websites/blogs/changelogs, Crunchbase/PitchBook, LinkedIn hiring patterns" and developer forums like "Discord, X, GitHub") and requires adding activity-log entries with "Source: [URL]" and using those signals to update battlecards/trigger HIGH alerts, so remote content can materially influence agent decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata