penetration-testing-methodology
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md shows the ReconnaissanceEngine actively fetching and parsing public web content (e.g., ReconnaissanceEngine._technology_detection uses requests.get("https://{domain}") and the workflow includes _web_crawling, _search_engine_recon and _social_media_recon), which clearly ingests untrusted, public third‑party content that the agent reads and uses to influence subsequent analysis and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata