finding-resources
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow mandates live web search/browsing and then incorporates/uses the retrieved page text (e.g., titles/authors/justification) from outsider-authored content across the public web when building the resource map.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill requires live web search and explicitly offers to install and run remote MCP packages (e.g., https://github.com/anthropics/brave-search-mcp, https://github.com/exalabs/exa-mcp-server, https://github.com/tavily-ai/tavily-mcp, https://github.com/serpapi/serpapi-mcp, https://github.com/modelcontextprotocol/servers/tree/main/src/fetch) via npx during runtime, which would fetch and execute remote code that the skill depends on.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata