competitive-teardown

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill’s required workflow ingests the user-supplied [COMPETITOR NAME/URL] into a free-text prompt (“Perform a competitive teardown of [COMPETITOR NAME/URL]”), and if that value is a URL or competitor text, it can cause the agent to fetch/reflect outsider-authored web content at runtime into the LLM context (public web content path via the competitor URL).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 01:20 PM
Issues
1
Security Audit — snyk — competitive-teardown