josh-braun-copywriting
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md instructs the workflow to use ColdIQ MCP/API to fetch/“extract” page content and other enrichment signals at runtime; those signals are not specified as being authored by the operating user, so the LLM context can include outsider-authored free text via
mcp__coldiq__fetch_page_content(and similar enrichment calls) from external sources.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata