langsmith-fetch
Warn
Audited by Snyk on Jul 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md describes running
langsmith-fetch traces ... --format pretty/jsonand then “analyz[ing] JSON and report”/“analyze and report,” which implies the CLI fetches execution traces/threads from LangSmith (outsider-authored content from other users’ agent runs) and turns them into readable text that the agent would ingest into its LLM context for analysis.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata