features
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes—during Deep Dive (optional/triggered) the required workflow delegates “web research” and/or “Explore” on user-provided URLs/documents, which can ingest outsider-authored free text into the LLM context via the web/extraction agent and then feed its findings into Phase 3–4.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata